The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.
https://wpscan.com/vulnerability/de28543b-c110-4a9f-bfe9-febccfba3a96