CVE-2026-13342: Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Security Optimizer (Security Optimizer – The All-In-One Protection Plugin)to a version that resolves this vulnerability.Fixed in 1.6.5 - Configuration
Update the Security Optimizer plugin to version 1.6.5 or later so that the IP-based login restriction feature properly validates requests and cannot be bypassed via post_password.
WordPress plugin: Security Optimizer (Security Optimizer – The All-In-One Protection Plugin) IP-based login restriction validation (optional IP allowlist for login access) = validated correctly (no allowlist bypass)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13342?
CVE-2026-13342 has a medium severity rating of 5.3.
How do I fix CVE-2026-13342?
To fix CVE-2026-13342, update the Security Optimizer plugin to version 1.6.5 or later.
What does CVE-2026-13342 exploit?
CVE-2026-13342 exploits the improper validation of requests in the IP-based login access feature of the Security Optimizer plugin.
What versions of the Security Optimizer plugin are affected by CVE-2026-13342?
CVE-2026-13342 affects Security Optimizer versions from 1.5.8 to 1.6.4.
What type of access does CVE-2026-13342 allow attackers to gain?
CVE-2026-13342 allows unauthenticated requests from non-allowlisted IP addresses to access the login form.