WordPress Plugin Vulnerabilities
Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
Description
The plugin does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-23 (about 16 days ago)
Added
2026-07-23 (about 15 days ago)
Last Updated
2026-07-23 (about 15 days ago)