WordPress Plugin Vulnerabilities

Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Account Email

Description

The plugin does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.

This affects sites where an administrator has populated the local username denylist, which is empty by default. Exploitation requires already holding valid credentials for the denylisted account, so it defeats the administrator's intended block rather than granting access that the password did not already grant. The case-sensitivity route applies to single-site installations; on multisite, WordPress normalises the submitted login before the plugin's check, leaving only the email address route.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 4 days ago)
Added
2026-08-17 (about 4 days ago)
Last Updated
2026-08-17 (about 4 days ago)

Other