• Resolved regisit

    (@regisit)


    Password checking is not working correctly. When a user resets a password from a link, it’s accepted ok but they still can’t login. When reset in admin, a perfectly valid password is blocked. Take SunnyBend#7565. 7565 is not allowed. Why? It’s not three consecutive numbers. Change it to SunnyBend#1975 and that’s allowed.

    Wordfence 8.1.0

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @regisit, thanks for getting in touch.

    We have an example in the code comments about repetition, such as “abab”, but “565” as 3 characters seems too short to be immediately apparent to most users if they come across the same issue. I managed to repeat this on a clean WordPress installation with Wordfence as this is the first time I’ve seen it mentioned.

    We can’t provide ongoing feedback about release dates or progress of product features here on the forums, but I have put the suggestion of changing this forward to the team for discussion next week. We may also update our documentation in the mean time to reflect its current requirements, in case anybody else comes across this.

    Many thanks,
    Peter.

    Plugin Support wfpeter

    (@wfpeter)

    Hi @regisit,

    We have updated https://www.wordfence.com/help/firewall/brute-force/ for the moment to match the way the plugin handles letters and numbers differently, and added two numeric examples.

    We will mark topics like this as “Resolved” but note that the suggestion to alter the behavior to 4 character repetition (such as “1212”) rather than triggering on “121” is now an open case in our internal issue tracking systems. We cannot provide direct feedback or potential release dates for changes here on the forums.

    Many thanks again,
    Peter.

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Password check not working as defined’ is closed to new replies.