CVE-2012-10001: Critical severity limit login attempts vulnerability
Published Jan 6, 2021
·Updated
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
Affected Software
1 affected component
Limit Login Attempts Project Limit Login Attempts Wordpress<1.7.1
Event History
Jan 6, 2021
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Limit Login Attempts plugin for WordPress?
The vulnerability ID is CVE-2012-10001.
2
What is the severity level of CVE-2012-10001?
The severity level of CVE-2012-10001 is 9.8 (critical).
3
How does CVE-2012-10001 affect the Limit Login Attempts plugin?
CVE-2012-10001 in the Limit Login Attempts plugin allows remote attackers to conduct brute-force authentication attempts.
4
What is the affected software for CVE-2012-10001?
The Limit Login Attempts plugin version up to 1.7.1 for WordPress is affected by CVE-2012-10001.
5
How can I fix CVE-2012-10001?
To fix CVE-2012-10001, you should update the Limit Login Attempts plugin to version 1.7.1 or later.