GHSA-c64r-rhpr-pqr5MediumCVSS 5.4
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every...
🔗 CVE IDs covered (1)
📋 Description
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.