Extension WordPress
Vulnérabilités Login Lockdown & Protection
Cette page rassemble les failles publiées pour Login Lockdown & Protection, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Login Lockdown & Protection
5 fiches
Login Lockdown & Protection <= 2.14 – IP Block Bypass
The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an…
*-2.14
2.15
12/12/2025
Login Lockdown & Protection <= 2.11 – Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelisting
The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated…
*-2.11
2.12
06/05/2025
Login Lockdown – Protect Login Form <= 2.08 – Missing Authorization
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it…
*-2.08
2.09
09/02/2024
Login Lockdown – Protect Login Form <= 2.06 – Authenticated(Administrator+) SQL Injection
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the 'iDisplayStart' parameter in all versions up to 2.07 (exclusive) due to insufficient escaping on the user supplied parameter and lack of…
[*, 2.07)
2.07
21/12/2023
Login Lockdown <= 2.06 – Authenticated (Administrator+) SQL Injection
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the ‘sort order and limit’ parameter in all versions up to 2.06 (inclusive) due to insufficient escaping on the user supplied parameter…
*-2.06
2.07
21/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.