WordPress Plugin Vulnerabilities

Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password

Description

The plugin does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.

Proof of Concept

Affects Plugins

Fixed in 1.6.5

References

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-07-23 (about 16 days ago)
Added
2026-07-23 (about 15 days ago)
Last Updated
2026-07-23 (about 15 days ago)

Other