The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-11-27T16:22:00.577Z
Updated: 2024-08-02T07:52:08.529Z
Reserved: 2023-09-27T17:21:24.474Z
Link: CVE-2023-5239
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-11-27T17:15:08.787
Modified: 2024-11-21T08:41:21.300
Link: CVE-2023-5239
Redhat
No data.