Access violation vulnerability in Login Lockdown & Protection 2.11

The Login Lockdown & Protection plugin for WordPress has a security vulnerability that allows unauthorized access to its features. This is because the plugin does not have a check in place to make sure only authorized users can use its functions. This means that attackers who have at least Subscriber-level access can get a special code that lets them add any IP address to the list of allowed users. This can only happen on new WordPress sites where the administrator has not yet visited the loginlockdown page.

Detected in:

Login Lockdown & Protection fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.