← WordPress Vulnerabilities
WordPress security by component

Login Lockdown & Protection

Login Lockdown & Protection is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Dec 13, 2025; the highest CVE/CNA score is 7.6.

Plugin slug: login-lockdown

CVE-2025-11707: Login Lockdown & Protection: A security weakness

Login Lockdown & Protection is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedDec 13, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 13, 2025 CVE-2025-11707
Login Lockdown & Protection: A security weakness
Login Lockdown & Protection is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
May 07, 2025 CVE-2025-3766
Login Lockdown & Protection: A security weakness
Login Lockdown & Protection is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Feb 29, 2024 CVE-2024-1340
Login Lockdown – Protect Login Form: A security weakness
Login Lockdown – Protect Login Form is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Dec 29, 2023 CVE-2023-50837
Login Lockdown – Protect Login Form: SQL injection
Login Lockdown – Protect Login Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2