CVE · Medium

CVE-2026-13342 — Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.6.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13342 Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.6.5 Protection Mechanism Failure Medium 5.3 < 1.6.5 1.6.5 2026-08-06

CVE-2026-13342

The Security Optimizer plugin versions 1.5.8 through 1.6.4 has a vulnerability where it fails to properly validate IP-based login restrictions. This flaw allows unauthenticated users from non-whitelisted IPs to access and use the login form, effectively circumventing the intended security controls set by the administrator.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.