IP Protection Bypass Vulnerability in WP Cerber Security Plugin
CVE-2022-4100

5.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
31 August 2024

Summary

The WP Cerber Security plugin for WordPress exhibits a vulnerability that compromises its IP Protection feature, enabling attackers to circumvent restrictions. This flaw arises from the plugin's failure to adequately verify a visitor's IP address, allowing individuals with blocked IPs to exploit the X-Forwarded-For HTTP header. By spoofing an allowed IP address in the header, unauthorized users can potentially gain access to resources that should be restricted. The vulnerability affects all versions of the WP Cerber Security plugin up to and including 9.4, posing a significant risk for WordPress sites relying on this security measure.

Affected Version(s)

WP Cerber Security, Anti-spam & Malware Scan * <= 9.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

chihyu
.