CyberRota Analysis
AI-GeneratedThe Block User Account plugin for WordPress prior to version 2.0.1 fails to enforce account blocking across all authentication methods, enabling blocked users with pre-existing application passwords to bypass restrictions and maintain full access to the REST API. This vulnerability poses a significant risk to site security, as it allows unauthorized actions by users who should be restricted. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.