WordPress.org

Ready to get started?Download WordPress

Forums

Limit Login Attempts
throws an error (2 posts)

  1. Mikkel Breum
    Member
    Posted 8 months ago #

    dprecated call and double declaration, kills WP after upgrade from 3.6.1 to 3.7.1

    http://wordpress.org/plugins/limit-login-attempts/

  2. kitchin
    Member
    Posted 6 months ago #

    What was the double declaration?

    I found one deprecated call, but you will only hit it in a specific situation when visiting your site legimately. If your cookie becomes invalid, for instance when migrating a WP install, it's at:

    Line 283
    $user = get_userdatabylogin($username);
    Should be:
    $user = get_user_by( 'login', $username )

    I guess this plugin is hard to test because you have to run it through attack scenarios. I only came across this bug because I did a migration.

    And like you say, upgrading can hit untested code paths.

Reply

You must log in to post.

About this Plugin

About this Topic

Tags

No tags yet.