GHSA-hxv9-fx39-qg4cMediumCVSS 5.3

The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests...

Published
August 7, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.

🔗 References (3)