Sceawere

Vulnerability Detail

CVE-2026-97308UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Login Lockdown Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.8
Creation Date
16h ago
Vendor
WebFactory
Product
Login Lockdown
Attack Type
CWE-290 Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.8",
  "pubDate": "2026-10-06T09:17:57.740Z",
  "pubdate": "2026-10-06T09:17:57.740Z",
  "executiveSummary": "An authentication bypass vulnerability exists in the Login Lockdown plugin for WordPress, specifically affecting versions 2.17 and prior. This security flaw allows unauthenticated remote attackers to circumvent the security controls implemented by the plugin. Designed to prevent brute-force attacks by limiting the number of login attempts from a given IP address, the plugin fails to properly validate or sanitize specific configuration parameters or request headers. As a result, attackers can continuously attempt to authenticate against the target WordPress site without triggering the lockdown mechanism.\nThe risk implications of this vulnerability are severe, as it directly undermines the primary defensive control of the plugin, exposing the site to automated credential stuffing and brute-force attacks. Successful exploitation does not require prior authentication or specialized privileges, making it highly accessible to external threat actors. To mitigate this risk, administrators must update the plugin to a patched version or implement alternative rate-limiting controls at the network or web application firewall layer.",
  "technicalDetails": "The root cause of the unauthenticated bypass vulnerability in Login Lockdown (versions <= 2.17) lies in the improper validation and sanitization of client-identifying headers used to track and restrict login attempts. The primary function of the Login Lockdown plugin is to record IP addresses of failed authentication attempts and temporarily block IP addresses that exceed a defined threshold. However, the plugin retrieves the client's IP address by querying standard PHP server variables, including HTTP headers such as 'HTTP_X_FORWARDED_FOR', 'HTTP_CLIENT_IP', and 'HTTP_X_REAL_IP', without verifying the trustworthiness of the intermediate network devices or proxy servers.\nThis implementation flaw enables an attacker to perform a header spoofing attack. The attack flow proceeds as follows: The attacker identifies a target WordPress site running Login Lockdown version 2.17 or earlier. The attacker then prepares an automated brute-force tool configured to target the standard WordPress login endpoint, typically 'wp-login.php' or 'xmlrpc.php'. With each sequential HTTP POST login request, the tool injects or rotates arbitrary values within the 'X-Forwarded-For' or 'Client-IP' HTTP headers.\nUpon receiving the request, the vulnerable plugin reads the manipulated header value, believing it represents the legitimate origin of the request. It logs the failed attempt against this arbitrary IP address. Because each subsequent request features a unique, spoofed IP address, the cumulative count of failed attempts for any single IP never exceeds the configured threshold (e.g., 3 failed attempts). Consequently, the lockdown trigger is bypassed entirely, allowing the attacker to maintain an uninterrupted stream of authentication attempts.\nThe vulnerable component resides in the IP retrieval helper functions within the plugin's core codebase. There are no special privileges or authentication states required to exploit this vulnerability, as the login interface is inherently exposed to the public network. The post-exploitation impact is severe, as potential outcomes include full administrative takeover of the WordPress instance, unauthorized data access, database modification, and lateral movement within the hosting environment if administrative credentials are successfully compromised.\nAdditionally, because the vulnerability allows the evasion of the plugin's core security control, the overall security posture of the application is significantly degraded. Security administrators relying solely on this plugin for brute-force mitigation are left with a false sense of security, unaware that automated scripts can easily bypass the restriction. This makes the vulnerability highly critical for installations that do not employ secondary defense-in-depth measures."
}
CVE-2026-97308: Login Lockdown Bypass Vulnerability (MEDIUM Severity, CVSS: 4.8) | Sceawere