Executive brief
A vulnerability exists in the WP Real IP-based Access Control plugin for WordPress, which is used to manage website access based on visitor IP addresses. An unauthenticated attacker can remotely inject malicious code into the plugin's settings. If a site administrator later views those settings, the malicious code will execute in their browser, potentially allowing the attacker to take over the website or steal sensitive administrative session information.
Technical details
The WP Real IP-based Access Control plugin through 1.3.1 suffers from an unauthenticated stored Cross-Site Scripting (XSS) vulnerability. The plugin's administrative file (get-real-ip-admin.php) performs a top-level option write for the 'acl_ctrl_addr' parameter on every admin-side request without verifying user capabilities or nonces. Because wp-admin/admin-ajax.php triggers this logic and is reachable by unauthenticated users, an attacker can overwrite plugin settings with a malicious payload. This payload is subsequently rendered without proper escaping on the plugin's settings page. When an administrator views the settings, the injected JavaScript executes in their security context, enabling full site compromise. As of the advisory date, no patch is available.
Affected products
- Unknown WP Real IP-based Access Control <= 1.3.1
Timeline
- 2026-07-09: disclosed: Publicly published by WPScan
- 2026-07-30: advisory: NVD published date