Medium severity6.5NVD Advisory· Published Feb 28, 2024· Updated Apr 8, 2026
CVE-2024-1860
CVE-2024-1860
Description
The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_add_whitelist() function in all versions up to, and including, 4.51. This makes it possible for unauthenticated attackers to add their IP Address to the whitelist circumventing protection
Affected products
2- Range: <=4.51
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/3d365284-73ac-4730-a83d-9202677cf161nvdThird Party Advisory
News mentions
0No linked articles in our index yet.