plugin

Ban Users Vulnerabilities

1 known security issue reported for the Ban Users WordPress plugin. Most recent disclosed Sep 12, 2023.

1 high

Running Ban Users on your site? Check whether your installed version is affected.

Scan your site free

BAN Users <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) Settings Update & Privilege Escalation

high

The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to a missing capability check on the 'w3dev_save_ban_user_settings_callback' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify the plu...

CVSS:
8.8
Affected:
up to 1.5.3
Fix:
No patched version reported
Disclosed:
Sep 12, 2023

CVE-2023-4153 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database