Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

William Cooke

#48306of 53,632
5.3Total CVSS
Vulnerabilities · 1
PT-2025-51054
5.3
2025-12-13
WordPress · Login Lockdown & Protection · CVE-2025-11707
**Name of the Vulnerable Software and Affected Versions** Login Lockdown & Protection plugin for WordPress versions up to and including 2.14 **Description** The Login Lockdown & Protection plugin for WordPress is susceptible to an IP block bypass. This occurs because the `$unblock key` key is not sufficiently random. Unauthenticated users who have access to an administrative user email can generate valid unblock keys for their IP address. This allows attackers to circumvent IP address blocks implemented to prevent brute-force login attempts. **Recommendations** Update the Login Lockdown & Protection plugin to a version later than 2.14.