IP Protection Bypass Vulnerability in WP Cerber Security Plugin
CVE-2022-4100
5.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 31 August 2024
Summary
The WP Cerber Security plugin for WordPress exhibits a vulnerability that compromises its IP Protection feature, enabling attackers to circumvent restrictions. This flaw arises from the plugin's failure to adequately verify a visitor's IP address, allowing individuals with blocked IPs to exploit the X-Forwarded-For HTTP header. By spoofing an allowed IP address in the header, unauthorized users can potentially gain access to resources that should be restricted. The vulnerability affects all versions of the WP Cerber Security plugin up to and including 9.4, posing a significant risk for WordPress sites relying on this security measure.
Affected Version(s)
WP Cerber Security, Anti-spam & Malware Scan * <= 9.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
chihyu