CVE-2026-18356: Unknown Limit Login Attempts Security

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.

Affected products

  • Unknown Limit Login Attempts Security: before 3.3.5 (fixed in 3.3.5)

Published 2026-08-21. Last modified 2026-08-26.