The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_add_whitelist() function in all versions up to, and including, 4.51. This makes it possible for unauthenticated attackers to add their IP Address to the whitelist circumventing protection
History

Tue, 11 Feb 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Billminozzi
Billminozzi anti Hacker
Weaknesses CWE-862
CPEs cpe:2.3:a:billminozzi:anti_hacker:*:*:*:*:*:wordpress:*:*
Vendors & Products Billminozzi
Billminozzi anti Hacker

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-04-22T15:58:09.817Z

Reserved: 2024-02-23T18:51:36.723Z

Link: CVE-2024-1860

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.305Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-28T10:15:09.320

Modified: 2025-02-11T20:12:01.223

Link: CVE-2024-1860

cve-icon Redhat

No data.