The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.
https://github.com/b0marek/CVE-2023-4800
https://wpscan.com/vulnerability/7eae1434-8c7a-4291-912d-a4a07b73ee56