What is CVE-2026-13342?
The Security Optimizer WordPress plugin (versions 1.5.8 to 1.6.4) fails to properly validate requests for its IP-based login restriction feature. This vulnerability (CVE-2026-13342) allows unauthenticated requests from non-allowlisted IP addresses to bypass the restriction and access the login form. Users should immediately update the plugin to the latest version.
Azərbaycanca: Security Optimizer WordPress plagini (1.5.8-1.6.4) IP-əsaslı giriş məhdudiyyəti funksiyasında sorğu validasiyası zəifliyi (CVE-2026-13342) aşkar edilib. Bu boşluq icazə verilməyən IP ünvanlardan gələn sorğuların məhdudiyyəti keçərək giriş formasına çatmasına imkan verir. İstifadəçilər plagini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Security Optimizer plugin are affected by CVE-2026-13342?
CVE-2026-13342 affects the Security Optimizer WordPress plugin versions 1.5.8 through 1.6.4.
How can I protect myself from the CVE-2026-13342 vulnerability?
Users should immediately update the Security Optimizer plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.