plugin

Restricted Site Access Vulnerabilities

7 known security issues reported for the Restricted Site Access WordPress plugin. Most recent disclosed Jun 4, 2024.

1 high 2 medium 2 low

Running Restricted Site Access on your site? Check whether your installed version is affected.

Scan your site free

Restricted Site Access [restricted-site-access] < 7.5.0

unknown

[en] Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Access: from n/a through 7.4.1.

Affected:
up to 7.5.0
Fixed in:
7.5.0
Disclosed:
Jun 4, 2024

CVE-2023-48753 on NVD →

Restricted Site Access <= 7.4.1 - IP Spoofing to Protection Mechanism Bypass

medium

The Restricted Site Access plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 6.3.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for user IP Addresses. This makes it possible for attackers to gain access to areas of the site th...

CVSS:
5.3
Affected:
up to 7.4.1
Fixed in:
7.5.0
Disclosed:
Nov 27, 2023

CVE-2023-48753 on NVD →

webpack JS package <= 5.75.0 - Sandbox Bypass

high

The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic comments. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.

CVSS:
8.3
Affected:
up to 7.3.5
Fixed in:
7.4.0
Disclosed:
Apr 11, 2023

CVE-2023-28154 on NVD →

loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service

low

The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the interpolateName function due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however,...

CVSS:
3.7
Affected:
up to 7.3.4
Fixed in:
7.3.5
Disclosed:
Oct 11, 2022

CVE-2022-37599 on NVD →

loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service

low

The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the resourcePath variable due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are...

CVSS:
3.7
Affected:
up to 7.3.4
Fixed in:
7.3.5
Disclosed:
Oct 11, 2022

CVE-2022-37603 on NVD →

Restricted Site Access [restricted-site-access] < 7.3.2

unknown

[en] The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.

Affected:
up to 7.3.2
Fixed in:
7.3.2
Disclosed:
Sep 26, 2022

CVE-2022-1613 on NVD →

Restricted Site Access <= 7.3.1 - Access Bypass via IP Spoofing

medium

The Restricted Site Access plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 7.3.1 due to prioritizing getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR. This makes it possible to bypass IP-based limitations in certain situations.

CVSS:
6.5
Affected:
up to 7.3.2
Fixed in:
7.3.2
Disclosed:
Aug 31, 2022

CVE-2022-1613 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database