CVE-2026-18356: CWE-184 Incomplete Blacklist in Limit Login Attempts Security
Description
The Limit Login Attempts Reloaded WordPress plugin versions before 3.3.5 contains an incomplete blacklist vulnerability. The plugin's username denylist does not perform case-insensitive comparisons and does not consider the account's email address. This allows an account that an administrator intended to block from logging in to bypass the restriction and authenticate successfully.
CVSS v3.1
Score 3.7low
Affected software
Limit Login Attempts Security
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18356 describes a vulnerability in the Limit Login Attempts Reloaded WordPress plugin prior to version 3.3.5. The flaw arises because the plugin's denylist for usernames is not checked in a case-insensitive manner and does not include checks against the email address associated with the account. Consequently, an attacker can circumvent login restrictions intended to block certain accounts, including administrator accounts, allowing unauthorized authentication.
Potential Impact
The vulnerability allows an attacker to bypass login restrictions imposed by the plugin's denylist, potentially enabling unauthorized authentication of accounts that should be blocked. The CVSS score of 3.7 (low severity) reflects limited impact, with no confidentiality or availability impact, and only low integrity impact. There are no known exploits in the wild.
Mitigation Recommendations
A fix is available in Limit Login Attempts Reloaded version 3.3.5. Users should upgrade to version 3.3.5 or later to address this vulnerability. No other mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-30T08:11:55.659Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a883c15acd9273b4916aa2f
Added to database: 08/21/2026, 11:52:53 UTC
Last enriched: 09/11/2026, 02:48:43 UTC
Last updated: 10/05/2026, 06:48:14 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.