CVE-2026-18356: Unknown Limit Login Attempts Security
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.
Affected products
- Unknown Limit Login Attempts Security: before 3.3.5 (fixed in 3.3.5)
Published 2026-08-21. Last modified 2026-08-26.