By default, WordPress allows unlimited login attempts, making it vulnerable to brute-force attacks. Use a plugin like to block an IP address after 3-5 failed attempts.
By default, WordPress allows unlimited login attempts, making it vulnerable to brute-force attacks. Use a plugin like to block an IP address after 3-5 failed attempts.