Security Optimizer Plugin Security Flaw Exposes Login Interface
CVE-2026-13342
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-13342?
The Security Optimizer WordPress plugin, versions 1.5.8 through 1.6.4, has a critical security flaw that allows bypassing the IP-based login restriction feature. This vulnerability occurs due to improper validation of requests, enabling unauthenticated users from non-allowlisted IPs to access the login form. This undermines the intended access controls set by administrators, making it essential for users to update the plugin to mitigate potential security risks.
Affected Version(s)
Security Optimizer 1.5.8 < 1.6.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved