The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-345 | |
CPEs | cpe:2.3:a:miniorange:web_application_firewall:*:*:*:*:*:wordpress:*:* |
Tue, 03 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Miniorange
Miniorange web Application Firewall |
|
CPEs | cpe:2.3:a:miniorange:web_application_firewall:*:*:*:*:*:*:*:* | |
Vendors & Products |
Miniorange
Miniorange web Application Firewall |
|
Metrics |
ssvc
|
Sat, 31 Aug 2024 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in. | |
Title | Web Application Firewall <= 2.1.2 - IP Address Spoofing to Protection Mechanism Bypass | |
Weaknesses | CWE-348 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-31T09:35:55.748Z
Updated: 2024-09-03T14:37:17.494Z
Reserved: 2022-12-16T02:14:06.131Z
Link: CVE-2022-4539
Vulnrichment
Updated: 2024-09-03T14:37:08.713Z
NVD
Status : Analyzed
Published: 2024-08-31T10:15:04.257
Modified: 2024-09-19T13:27:53.407
Link: CVE-2022-4539
Redhat
No data.