Description
WordPress Plugin WP-Ban is prone to a security bypass vulnerability. Attackers can exploit this vulnerability in some circumstances by setting the "X-Forwarded-For" HTTP header field and thus bypassing IP blacklisting functionality. WordPress Plugin WP-Ban version 1.63 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.64 or latest
References
http://packetstormsecurity.com/files/128292/WordPress-WP-Ban-1.62-Bypass.html
Related Vulnerabilities
MySQL CVE-2024-21090 Vulnerability (CVE-2024-21090)
WordPress Plugin EWWW Image Optimizer Cross-Site Request Forgery (5.8.1)
WordPress Plugin MF Gig Calendar 'page_id' Parameter Cross-Site Scripting (0.9.4.1)
WordPress Plugin Advanced User Registration and Management Cross-Site Scripting (2.3.5)
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36155)