PT-2025-51054 · WordPress · Login Lockdown & Protection

William Cooke

·

Published

2025-12-13

·

Updated

2025-12-13

·

CVE-2025-11707

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Login Lockdown & Protection plugin for WordPress versions up to and including 2.14
Description The Login Lockdown & Protection plugin for WordPress is susceptible to an IP block bypass. This occurs because the $unblock key key is not sufficiently random. Unauthenticated users who have access to an administrative user email can generate valid unblock keys for their IP address. This allows attackers to circumvent IP address blocks implemented to prevent brute-force login attempts.
Recommendations Update the Login Lockdown & Protection plugin to a version later than 2.14.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2025-11707

Affected Products

Login Lockdown & Protection