Ghostwire

CVE-2026-14592: The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks...

HIGH CVSS 0.0

Published: July 30, 2026 | Last Modified: July 30, 2026

Description

The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any administrator who views the page.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References