I’ve been trying to make custom changes to the login error messages displayed on by altering the user.php file in wp-includes.
The default messages are displayed in plain text, so “<strong>ERROR</strong>” pops up on every single error, and looks ridiculous. Additionally, I want my own words in there… to insert some comedy in the messaging.
Anyhow, I make changes, and maybe a few weeks down the road… they’re gone.
I have no idea why user.php is being overwritten… if it’s a theme change, or an update that’s doing it… but I’ve definitely changed it for the last time before figuring out what the heck is going on here.
Any ideas on how I can stabilize user.php and keep my custom messages?
]]>I have installed activity log yesterday. One log I can see and yet not clear of it was
IP: Different IPs
Type: POST
Label : Blank
Action: Wrong Password
Description: admin
for IPS it is catching different IPs when I am the only admin user and I never attempted to login. Please explain.
Regards.
]]>She is not using TFA. I’ve tried using an incognito window to avoid LastPass. Have reset password several times. She deleted the first user, added a second time with new username as editor. I can get to the login screen, it just won’t accept the password.
Neither of us are very knowledgable for many of the background setting changes suggested in other forums. Is there an easy answer?
Website is wordpress.com. Can someone point me in the right direction?
]]>NinjaFirewall block user immediately if first password enter is wrong. I have to deactivate the firewall to restore the login page.
It came to my attention after I entered the wrong password when I tested an account. Can I change this?
Login protection is not active.
Kind regards
]]>Looking for some help!
So I am building a WordPress site. And the ultimate member plugin is doing good but then I just noticed something weird.
So, I have a test profile, when I tried to log in with wrong password, my admin log in was affected and said the usual I have to wait for 20 minutes. So I made another test profile and same problem, all profiles cannot log in within that 20 minute time frame. I hope I explained this correctly. Can someone help? Thanks!!
]]>Our site has so many (~20k/day) “Wrong Password” even if we use captcha v3, disabled xmlrpc and json api.
We have strong password policy as well but this attack is still disturbing.
How this plugin counts “Wrong Password”?
Do you think the attempts blocked by captcha logged as well? (however I only see high score attempts on google dashboard)
And what about the unauthorized API responses? Are they recorded?
Thanks in advance,
Laszlo
PLEASE let me know how to fix this.
]]>