From ca80c54e3b14315fba67c90ccfd5247e23b06dd7 Mon Sep 17 00:00:00 2001 From: Glomberg Date: Tue, 29 Sep 2026 16:55:34 +0300 Subject: [PATCH 1/3] Upb. BFP. Lost password requests protection implemented. --- inc/spbc-auth.php | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/inc/spbc-auth.php b/inc/spbc-auth.php index 05efec2b4..03453f9c9 100644 --- a/inc/spbc-auth.php +++ b/inc/spbc-auth.php @@ -22,7 +22,8 @@ die('Not allowed!'); } -add_filter('authenticate', 'spbc_authenticate', 20, 2); // Hooks for authentificate +add_filter('authenticate', 'spbc_authenticate', 20, 2); // Hooks for authenticate +add_filter('lostpassword_errors', 'spbc_lostpassword_rate_limit', 20, 2); // Hooks for lost password request checking // Hook for token-based logins (plugins like "Temporary Login Without Password") add_action('set_logged_in_cookie', 'spbc_detect_token_login', 10, 6); @@ -266,6 +267,24 @@ function spbc_authenticate($user, $username) return $user; } +function spbc_lostpassword_rate_limit($error) +{ + global $spbc; + $limit = !empty($spbc->settings['bfp__allowed_wrong_auths']) + ? (int) $spbc->settings['bfp__allowed_wrong_auths'] + : 5; + $period = !empty($spbc->settings['bfp__block_period__5_fails']) + ? (int) $spbc->settings['bfp__block_period__5_fails'] + : 3600; + $config = new RateLimiterConfig('lostpassword_rate_limit', $limit, $period); + $rate_limiter = new SpbcRateLimiter($config); + $rate_limiter_check = $rate_limiter->checkPassed(); + if ( ! $rate_limiter_check ) { + return new WP_Error(403, 'Limit exceeded'); + } + return $error; +} + /** * Detecting new device * From 50f6d523be1eae7a70a76f35be2300dd8a29bd09 Mon Sep 17 00:00:00 2001 From: Glomberg Date: Tue, 29 Sep 2026 17:50:37 +0300 Subject: [PATCH 2/3] Fix. Security. Lost password requests protection fix - hook changed. --- inc/spbc-auth.php | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/inc/spbc-auth.php b/inc/spbc-auth.php index 03453f9c9..f01ecf187 100644 --- a/inc/spbc-auth.php +++ b/inc/spbc-auth.php @@ -23,7 +23,7 @@ } add_filter('authenticate', 'spbc_authenticate', 20, 2); // Hooks for authenticate -add_filter('lostpassword_errors', 'spbc_lostpassword_rate_limit', 20, 2); // Hooks for lost password request checking +add_action('lostpassword_post', 'spbc_lostpassword_rate_limit', 20, 2); // Hooks for lost password request checking // Hook for token-based logins (plugins like "Temporary Login Without Password") add_action('set_logged_in_cookie', 'spbc_detect_token_login', 10, 6); @@ -280,7 +280,13 @@ function spbc_lostpassword_rate_limit($error) $rate_limiter = new SpbcRateLimiter($config); $rate_limiter_check = $rate_limiter->checkPassed(); if ( ! $rate_limiter_check ) { - return new WP_Error(403, 'Limit exceeded'); + $limit_message = esc_html__('Current route access denied. (Security by CleanTalk)', 'security-malware-firewall'); + add_filter('lostpassword_errors', function($_errors, $_user) use ($limit_message) { + return new WP_Error(403, $limit_message); + }, 20, 2); + if (function_exists('wc_add_notice')) { + wp_die($limit_message, '', ['response' => 403]); + } } return $error; } From 4e1b3cc1a2eb03b70a4bab73bfd8f5e44072e8a3 Mon Sep 17 00:00:00 2001 From: Glomberg Date: Wed, 30 Sep 2026 14:42:24 +0300 Subject: [PATCH 3/3] Dev. Code. Code style fixed. --- inc/spbc-auth.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/inc/spbc-auth.php b/inc/spbc-auth.php index f01ecf187..1c60b3a99 100644 --- a/inc/spbc-auth.php +++ b/inc/spbc-auth.php @@ -281,7 +281,7 @@ function spbc_lostpassword_rate_limit($error) $rate_limiter_check = $rate_limiter->checkPassed(); if ( ! $rate_limiter_check ) { $limit_message = esc_html__('Current route access denied. (Security by CleanTalk)', 'security-malware-firewall'); - add_filter('lostpassword_errors', function($_errors, $_user) use ($limit_message) { + add_filter('lostpassword_errors', function ($_errors, $_user) use ($limit_message) { return new WP_Error(403, $limit_message); }, 20, 2); if (function_exists('wc_add_notice')) {