CVE-2026-18356 PUBLISHED

Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Account Email

Assigner: WPScan
Reserved: 30.07.2026 Published: 21.08.2026 Updated: 21.08.2026

The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 3.7

Product Status

Vendor Unknown
Product Limit Login Attempts Security
Versions Default: unaffected
  • affected from 0 to 3.3.5 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-184 Incomplete Blacklist CWE