Weak configuration vulnerability in Banhammer – Monitor Site Traffic, Block Bad Users and Bots 3.4.8

The Banhammer plugin for WordPress has a vulnerability that allows attackers to bypass its protection measures. This is because the plugin uses a predictable “secret key” to store information, making it easy for attackers to manipulate and override the plugin’s functions. This vulnerability affects all versions of the plugin up to 3.4.8. If you have this plugin installed, it is recommended to update to a newer version to fix this issue.

Detected in:

Banhammer – Monitor Site Traffic, Block Bad Users and Bots fixed vulnerable versions: >= * <= 3.4.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.