Weak configuration vulnerability in Lock User Account 1.0.5

The Lock User Account plugin for WordPress can be hacked by anyone using an older version (1.0.5 or earlier). This is because the plugin allows people to log in with a special password even if their account is locked. This means that someone who shouldn’t have access to the site can still use it through an API like XML-RPC or REST.

Detected in:

Lock User Account open vulnerable versions: >= * <= 1.0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.