ok, so it seems I overlooked a previous question asked here on stackexchange.
For anyone interested, the solution might be found here:
brute force attack even though it is limited by IP
Related Posts:
- Brute force attack?
- Is there any way to rename or hide wp-login.php?
- Increase of failed login attempts, brute force attacks? [closed]
- How to fake a WordPress login?
- Receiving “This content cannot be displayed in a frame” error on login page
- Websites defaced by uploading script using theme editor
- Make wordpress admin failed login attempt return 401
- Can’t stop hacker trying to get admin access in WordPress blog after trying many ways [closed]
- Store brute-force IP addresses
- How to create a private login page for admin.?
- WordPress Security – How to block alternative WordPress access
- Protecting WordPress login page
- wp-admin folder, brute force, and password protection
- Sniffing wordpress user’s credentials
- disable site_url redirect in wp-login.php
- Does WordPress (or a plugin) reveal login credentials to admin?
- Is wp_login_form secure on a non secure page?
- WordPress login security
- Why isn’t the login page rate limited by default?
- How can I password protect a WordPress site without requiring users to log in?
- Input sanitation
- How to Prevent Brute Force Attack on WordPress
- Advice on redirect to lock site from unauthorized users
- Where is the php file, that does the checks for login information?
- Error on WordPress Login
- Access log “POST /wp-login.php HTTP/1.0” 400
- force login loophole
- I need to find which is the file that checks the DB for correct login (username, password)
- How to create separate login for authors/moderators/subscribers?
- How to invalidate `password reset key` after being used
- Site is not loading after relogin attempts on SSL
- Some crawlers/bots attempting to login with very good guesses. How?
- Hide wp-login.php but not the widget
- How login is possible, if I deny login page via nginx?
- I can’t access my site via wp-admin
- Website Visible only to Registered users
- How do I use add_action from a class method?
- I want to disable E-Mail verifcation / activation when a user signs up for my WordPress site
- How do I check if a post is private?
- Display last login time
- What hooks should I use for pre-login and pre-registration actions?
- how to update current logged user username
- Custom Reset Password & Forgot Password Front End Forms
- How to implement Google reCaptcha without installing a plugin?
- Problem with logging in WP users automatically
- advance membership managment
- Security issues with WP sites
- Different homepage for logged in users
- reset password link redirect to login page
- Deregister default wp-admin css on login screen only?
- Should I encrypt the response that triggers an Ajax action? Is nonce sufficient?
- How can I login as admin after redirect to custom login page
- is_user_logged_in() not working in Firefox
- WordPress Cant access wp-login.php
- How to remove ‘wordpress…’ text from page titles in tabs
- Using gettext to translate wp-login.php can’t translate `Back to` into other language
- Code for Log Out Button Yields Strange URL
- Display first name instead of username
- How can I make a login just like on wordpress.org?
- How can I insert wordpress login screen on a different domain?
- autocomplete=”off” WordPress Login
- Why there is a 302 status when my account and password are right?
- 503 Login WordPress [closed]
- Password recovery URL has error – but not found in code or db
- Cannot Get User id after login success in file wp_login.php
- If I use an alternative login (e.g. CAS or other SSO) plugin, is my site protected from the recent brute force login attempts?
- This webpage has a redirect loop issue
- authenticate user without redirecting
- Create front end member login
- Logging in to the frontend works correctly but not for WP-Admin
- Cannot login to WordPress on one device: login refreshes/an error was encountered whilst trying to authenticate
- Make an order of products without login
- Updated : how to make email optional while user registration using default wordpress form
- I can’t log in to `wp-admin` after changing my domain
- My wordpress site crashes when I login!
- Bypass login page
- Using WordPress login for a non word-press website
- Using is_user_logged_in() to lock down whole site
- https rewrite not working for All in one security Brute force > rename login url
- After moving WordPress to its own directory, login doesn’t work
- WordPress login is not showing , there is warning?
- WordPress Redirect After logging
- Issue logging in from second computer
- Login problem with https
- How to Create a login for for subscribers only
- WordPress auto login user after registration only from a specific page
- Custom Field For Login
- User login without username, only password
- Login user after registration programmatically
- wp_lostpassword_url not escaped
- Directory authentication initially succeeded, but no valid profile was found (“get entries” procedure)
- Trim the repeated value in URL
- Warning: session_start(): Cannot send session cookie – headers already sent by
- Login to wordpress with filezilla client [closed]
- Member Area Login with Fail Message
- How to Find WordPress site has backdoor login Codes
- Username character requirements
- Users cannot log in using popup
- Remove login link from Reset Password-screen
- Display number of consecutive days a user has been active on the site