Description
WordPress Plugin SecuPress Free-WordPress Security is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently ban any IP. WordPress Plugin SecuPress Free-WordPress Security version 1.4.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0 or latest
References
Related Vulnerabilities
WordPress Plugin Import any XML or CSV File to WordPress Arbitrary File Upload (3.6.7)
WordPress Plugin Content Cards Cross-Site Scripting (0.9.6)
WordPress Plugin Newsletter Open Redirect (3.7.0)
WordPress Plugin Custom Text Selection Colors Cross-Site Scripting (1.0)
WordPress Plugin Events by Devllo Cross-Site Scripting (1.0.4.2)