CyberRota Analysis
AI-GeneratedThe WP Real IP-based Access Control plugin for WordPress versions up to 1.3.1 is vulnerable due to a lack of capability and nonce checks, allowing unauthenticated users to inject arbitrary JavaScript into its settings page. This can lead to cross-site scripting (XSS) attacks, potentially compromising the security of administrators who access the page. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate the risk.
Original NVD Description
The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any administrator who views the page.