Medium 4.3
2025-04-28< 2.3.10
SecuPress Free <= 2.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
Minimum safe version
2.3.10
Update to 2.3.10 or later to address 7 fixable vulnerabilities
SecuPress Free <= 2.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
CVE-2025-30907
CVE-2024-43228
SecuPress Free — WordPress Security <= 2.2.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via secupress_check_ban_ips_form Shortcode
CVE-2024-1504
SecuPress < 2.0 - Unauthenticated Arbitrary IP Ban
SecuPress Free and SecuPress Pro <= 1.4.12 - Unauthenticated Arbitrary IP Ban