CVE-2026-18356

Summary

The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.

Affected Software

VendorProductVersion RangeStatus
UnknownLimit Login Attempts Security0 < 3.3.5affected

Weaknesses

  • CWE-184 Incomplete Blacklist

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References