CVE-2026-13342 MEDIUM

CVE-2026-13342: Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password

Vendor Unknown
Product Security Optimizer
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.

Explanation of Vulnerability in Simple Terms

02Summary

Security Optimizer versions 1.5.8 through 1.6.4 contain an integrity vulnerability accessible over the network without authentication or user interaction. An attacker can modify data or content on the site. The vulnerability does not affect confidentiality or availability. Update to version 1.6.5 or later.

What an attacker can do

03Attacker Capabilities

Modify data or content on the site without authentication.

Potential impact on your site

04Site Impact

Attackers can alter site data, content, or settings without logging in.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published