Restricted Site Access [restricted-site-access] < 7.5.0
unknown
[en] Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Access: from n/a through 7.4.1.
- Affected:
- up to 7.5.0
- Fixed in:
- 7.5.0
- Disclosed:
- Jun 4, 2024
CVE-2023-48753 on NVD →
Restricted Site Access <= 7.4.1 - IP Spoofing to Protection Mechanism Bypass
medium
The Restricted Site Access plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 6.3.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for user IP Addresses. This makes it possible for attackers to gain access to areas of the site th...
- CVSS:
- 5.3
- Affected:
- up to 7.4.1
- Fixed in:
- 7.5.0
- Disclosed:
- Nov 27, 2023
CVE-2023-48753 on NVD →
webpack JS package <= 5.75.0 - Sandbox Bypass
high
The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic comments. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.
- CVSS:
- 8.3
- Affected:
- up to 7.3.5
- Fixed in:
- 7.4.0
- Disclosed:
- Apr 11, 2023
CVE-2023-28154 on NVD →
loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service
low
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the interpolateName function due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however,...
- CVSS:
- 3.7
- Affected:
- up to 7.3.4
- Fixed in:
- 7.3.5
- Disclosed:
- Oct 11, 2022
CVE-2022-37599 on NVD →
loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service
low
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the resourcePath variable due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are...
- CVSS:
- 3.7
- Affected:
- up to 7.3.4
- Fixed in:
- 7.3.5
- Disclosed:
- Oct 11, 2022
CVE-2022-37603 on NVD →
Restricted Site Access [restricted-site-access] < 7.3.2
unknown
[en] The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.
- Affected:
- up to 7.3.2
- Fixed in:
- 7.3.2
- Disclosed:
- Sep 26, 2022
CVE-2022-1613 on NVD →
Restricted Site Access <= 7.3.1 - Access Bypass via IP Spoofing
medium
The Restricted Site Access plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 7.3.1
due to prioritizing getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR. This makes it possible to bypass IP-based limitations in certain situations.
- CVSS:
- 6.5
- Affected:
- up to 7.3.2
- Fixed in:
- 7.3.2
- Disclosed:
- Aug 31, 2022
CVE-2022-1613 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database