WP Ban Project maintains a WordPress security plugin focused on access control and ban management, representing a narrowly scoped but specialized addition to the WordPress ecosystem. The observed vulnerabilities center on the plugin's authentication and access-control mechanisms, reflecting the sensitivity of its role in site protection. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Ban Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4260MEDIUM The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scrip | Jan 2, 2023 | 4.8 | 28 | NO | YES |
CVE-2022-4631MEDIUM A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripti | Dec 21, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-4252MEDIUM A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the | Dec 18, 2022 | 6.1 | 21 | NO | NO |
CVE-2014-6230MEDIUM WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header. | Oct 25, 2014 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Ban Project.
Media articles that mention a CVE ID that affects a product developed by Wp Ban Project — matched by CVE ID, not by vendor name.