WP-Ban
WP-Ban has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2022; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Improper Input Validation.
Every one of the 2 issues recorded for WP-Ban has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. WP-Ban is installed on roughly 8,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-4260WP-Ban <= 1.69 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP-Ban
Author
Lester Chan
Banned visitors are served a custom message instead of your site. You can ban by IP address, IP range, host name, user agent or referrer URL, exclude specific addresses from ever being banned, and see how many times each banned visitor has tried to get in. Wildcards are supported throughout. Everything is configured under Settings -> Ban, on three tabs: Stats for the attempt counters, Settings for the ban lists and the visitor IP options, and Templates for the banned message. The plugin will not let you ban the address, host name or user agent you are currently browsing with, so a wildcard that would lock you out of your own site is refused at save time and the screen says which entry it dropped. Features Ban by IP address, IP range, host name, user agent or referrer URL Wildcards in every list except IP ranges and the exclude list IPv4 and IPv6, including IPv6 ranges An exclude list that wins over every other list Your own banned message, as a complete HTML document, with a live preview A sortable, paginated count of how many times each banned visitor has tried Self-ban protection that protects whoever is saving, not just a user called “admin” Donations I spent most of my free time creating, updating, maintaining and supporting these plugins, if you really love my plugins and could spare me a couple of bucks, I will really appreciate it. If not feel free to use it without any obligations. Usage Go to Settings -> Ban. The screen has three tabs and opens on Stats. On the Settings tab, fill in the lists you want. Every list matches the whole value, so use * where you want a partial match: 192.168.1.* bans that whole block, EmailSiphon* bans every user agent starting with that name. IP ranges are written as start-end, one per line. IPv4 and IPv6 are both supported, but a single range cannot mix the two. The Templates tab holds the banned message on its own, because it is a whole HTML document and burying it under six textareas made the screen a wall. The Stats tab is the attempt counters, twenty rows at a time, sortable by address or by attempts. Tick the rows you want cleared and use the bulk action, or tick Reset every IP ban stat and the total to start again. All three tabs write the same wp_ban_options row, so saving one never disturbs what the other two hold. WP-CLI wp ban list wp ban list ips wp ban add ips 192.168.1.100 wp ban add ips '192.168.1.*' wp ban add ips_range 192.168.1.1-192.168.1.255 wp ban remove ips 192.168.1.100 --yes wp ban check 192.168.1.55 wp ban stats wp ban reset --all --yes The lists are ips, ips_range, hosts, referers, user_agents and exclude_ips — the same six the Settings tab shows, in the same order. Quote any entry containing a *, or the shell will try to expand it into filenames. wp ban check runs the same match every visitor's request runs, against an address you name, and reports whether it would be banned and by which list. Ranges and wildcards cover far more than they look like they do, so this is worth running before you add one and after you have. It writes nothing and counts nothing, so an address you check does not appear in `wp ban stats`. wp ban remove and `wp ban reset` ask before they act; pass `--yes` in a script. Two differences from the screen. The Settings tab refuses to add an entry that matches the administrator saving it, and a shell has no visitor to protect, so the command adds what you tell it to — check first. And the Stats tab shows a host name per row, which the command does not, because that is a DNS lookup per address and the screen only pays it for the rows it is displaying. Filters Use wp_ban_enabled to skip the ban check for some requests: add_filter( 'wp_ban_enabled', function ( $enabled ) { return ! defined( 'REST_REQUEST' ) || ! REST_REQUEST; } ); Use wp_ban_denied to do something else when a visitor is turned away: add_action( 'wp_ban_denied', function ( $ip, $status ) { error_log( 'WP-Ban turned away ' . $ip ); }, 10, 2 ); Use wp_ban_capability to hand the screen to a capability other than manage_options: add_filter( 'wp_ban_capability', function ( $capability, $context ) { return 'edit_pages'; }, 10, 2 ); The other four are wp_ban_ipaddress (the address a request is attributed to), wp_ban_status_code (the HTTP status the ban page is served with), wp_ban_protect_self (whether self-ban protection runs) and wp_ban_trust_proxy (whether the usual forwarding headers may be trusted).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C