• Resolved David Adams

    (@tictag)


    I have a user who was locked out by Wordfence v8.0.2 because she entered an incorrect username but on reviewing the WordPress > Users page, she had entered the correct username. How should I troubleshoot this?

    I have a screenshot – is there somewhere secure I can send it (it contains her username)?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @tictag,

    Depending on the strictness of your settings, users can be locked out for attempting their email address rather than username. You could send the screenshot to wftest @ wordfence . com. Please include your forum username in the subject and reply here once you’ve sent it so we can take a look.

    Thanks,
    Peter.

    Thread Starter David Adams

    (@tictag)

    Screenshot sent.
    David.

    Plugin Support wfpeter

    (@wfpeter)

    Hi @tictag, thanks so much for sending that over.

    This is an issue we have entered a case to resolve in a future update. In testing, if the username for an account is an email address, log in works under regular circumstances but if we use an incorrect password once, a block will be triggered for: Used an invalid username 'zxcvbnm@zxcvbnm.com' to try to sign in. They will be blocked immediately rather than being given the amount of failed password attempts specified in your Brute Force settings.

    If the block has already lapsed, they can try again with the correct password (if known) or use the “Lost your password” link on the WordPress login page to reset it to something memorable in the mean time.

    Thanks,
    Peter.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘User Lockout With Correct Username’ is closed to new replies.