The Limit Login Attempts plugin prior to 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote malicious users to conduct brute-force authentication attempts.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
limit login attempts project limit login attempts |