CVE-2026-97308: WordPress Login Lockdown plugin <= 2.17 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Login Lockdown pluginto a version that resolves this vulnerability.Fixed in 2.18
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or prior access to attempt exploitation. The attack vector is network-based, meaning the affected site must be reachable over the network.
Which installations are affected?
WordPress sites using the Login Lockdown plugin version 2.17 or earlier are identified as affected. The provided data does not state whether a particular plugin configuration is required.
How difficult is exploitation expected to be?
The CVSS vector lists high attack complexity, indicating exploitation requires conditions beyond simply sending a basic request. No user interaction or attacker privileges are required according to the supplied vector.
What impact is indicated?
The supplied CVSS vector indicates low confidentiality and low integrity impact, with no availability impact. The issue is rated medium severity with a CVSS score of 4.8.