Description
WordPress Plugin WP-Ban is prone to a security bypass vulnerability. Attackers can exploit this vulnerability in some circumstances by setting the "X-Forwarded-For" HTTP header field and thus bypassing IP blacklisting functionality. WordPress Plugin WP-Ban version 1.63 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.64 or latest
References
http://packetstormsecurity.com/files/128292/WordPress-WP-Ban-1.62-Bypass.html
Related Vulnerabilities
Apache HTTP Server CVE-2003-0789 Vulnerability (CVE-2003-0789)
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2020-1971)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3579)
IBM WebSEAL CVE-2019-4135 Vulnerability (CVE-2019-4135)
MediaWiki Resource Management Errors Vulnerability (CVE-2015-2936)