VYPR

WP Real IP-based Access Control

by WordPress

CVEs (1)

  • CVE-2026-14592Jul 30, 2026
    risk 0.00cvss epss 0.00

    The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript…