IP Protection Bypass Vulnerability in WP Cerber Security Plugin
CVE-2022-4100
5.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 31 August 2024
What is CVE-2022-4100?
The WP Cerber Security plugin for WordPress exhibits a vulnerability that compromises its IP Protection feature, enabling attackers to circumvent restrictions. This flaw arises from the plugin's failure to adequately verify a visitor's IP address, allowing individuals with blocked IPs to exploit the X-Forwarded-For HTTP header. By spoofing an allowed IP address in the header, unauthorized users can potentially gain access to resources that should be restricted. The vulnerability affects all versions of the WP Cerber Security plugin up to and including 9.4, posing a significant risk for WordPress sites relying on this security measure.
Affected Version(s)
WP Cerber Security, Anti-spam & Malware Scan * <= 9.4