---
id: CVE-2025-11707
title: >-
  The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block
  Bypass in all versions up to, and including, 2.14
summary: >-
  The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block
  Bypass in all versions up to, and including, 2.14. This is due to $unblock_key
  key being insufficiently random allowing unauthenticated users, with access to
  …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-330
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11707'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/login-lockdown/trunk/libs/functions.php
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3389843%40login-lockdown&new=3389843%40login-lockdown&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/9c732ea2-0263-4b18-9aa4-29e387b26362?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00451
epssPercentile: 0.37119
ingestedAt: '2026-10-07T20:46:46.925Z'
---

## Overview

The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Address. This makes it possible for unauthenticated attackers to bypass blocks due to invalid login attempts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
