cvedb.io
CVE-2026-13342
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2026-08-06T22:16:45.583 · Last modified 2026-08-06T22:16:45.583

Summary

The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.