Security vulnerabilities in Limit Login Attempts Reloaded (1)
-
DOS through IP spoofing – (Limit Login Attempts Reloaded <= 2.25.5)
An attacker can exploit this to ban legitimate users or the site’s own reverse proxy from making requests to the wp-login endpoint which prevents anybody from logging into the site.