SecuPress Free and SecuPress Pro <= 1.4.12 - Unauthenticated Arbitrary IP Ban

2021-03-22 00:00
Anonymous

Strategic Overview

Status
Patched in 2.0
Affected PluginSecuPress Pro
Affected Version< 2.0
CVSS7.5High
CVEN/A
View all SecuPress Pro vulnerabilities

Vulnerability Overview

The SecuPress Free and SecuPress Pro plugins for WordPress is vulnerable to unauthenticated arbitrary IP bans in versions up to, and including, 1.4.12. This makes it possible for unauthenticated remote attackers to ban any IP address from accessing the site.

Technical Analysis

REMEDIATION: Update to version 2.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C