Impact
The Security Optimizer WordPress plugin, in versions ranging from 1.5.8 to 1.6.4, fails to properly validate requests that invoke its optional IP‑based login restriction. As a result, unauthenticated requests originating from IP addresses that are not on the allowlist can still reach and interact with the login form, negating the administrator‑configured access control. This flaw allows an attacker who cannot directly log in but can target the login endpoint to bypass IP restrictions and attempt credential compromise.
Affected Systems
WordPress websites running the Security Optimizer plugin versions 1.5.8 through 1.6.4 are affected. The vulnerability specifically impacts installations where the IP‑based login restriction feature has been enabled.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been documented. The likely attack vector is web‑based; an attacker can send requests to the post_password endpoint from any IP and circumvent the allowed‑list check. The exploit requires the plugin to be installed and the IP‑restriction feature to be enabled. Attackers could therefore launch brute‑force or credential‑guessing attempts from arbitrary IPs, potentially compromising site accounts if passwords are weak or reused.
OpenCVE Enrichment