Input validation vulnerability in WP Limit Login Attempts 2.6.4

The WP Limit Login Attempts plugin for WordPress (up to version 2.6.4) is not secure. Attackers can use something called IP Address Spoofing to get around restrictions that the plugin puts in place. IP Address Spoofing means that attackers can supply a fake IP Address in a special header. This fake IP Address can help them bypass the settings that are meant to block out their real IP Address.

Detected in:

WP Limit Login Attempts fixed vulnerable versions: >= * <= 2.6.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.