Description
WordPress Plugin WP-Ban is prone to a security bypass vulnerability. Attackers can exploit this vulnerability in some circumstances by setting the "X-Forwarded-For" HTTP header field and thus bypassing IP blacklisting functionality. WordPress Plugin WP-Ban version 1.63 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.64 or latest
References
http://packetstormsecurity.com/files/128292/WordPress-WP-Ban-1.62-Bypass.html