Description
WordPress Plugin SecuPress Free-WordPress Security is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently ban any IP. WordPress Plugin SecuPress Free-WordPress Security version 1.4.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0 or latest
References
Related Vulnerabilities
WordPress Plugin Filter Custom Fields & Taxonomies Light Unspecified Vulnerability (1.04)
WordPress Plugin Comments-wpDiscuz SQL Injection (5.3.5)
phpBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1627)
Oracle JRE CVE-2013-0428 Vulnerability (CVE-2013-0428)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17304)