Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 21 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-184 | |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway. | |
| Title | Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Account Email | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-21T12:46:58.438Z
Reserved: 2026-07-30T08:11:55.659Z
Link: CVE-2026-18356
Updated: 2026-08-21T12:46:47.218Z
Status : Received
Published: 2026-08-21T12:16:24.863
Modified: 2026-08-21T13:16:55.130
Link: CVE-2026-18356
No data.
OpenCVE Enrichment
Updated: 2026-08-21T13:30:04Z