IP Address Spoofing Vulnerability in WP Firewall Plugin
CVE-2022-4536

5.3MEDIUM

What is CVE-2022-4536?

The WP Firewall plugin for WordPress is affected by a vulnerability that permits IP Address Spoofing in versions up to and including 1.1. This issue arises from inadequate restrictions on the sources from which IP Address information is fetched for request logging and login restrictions. Malicious actors can exploit this flaw by providing a maliciously crafted X-Forwarded-For header, which allows them to log in with an IP address that may have been previously blocked. As a result, normal security measures that deny access to specific IP addresses or geographic locations can be circumvented, potentially leading to unauthorized access and further exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Two-factor authentication (formerly IP Vault) * <= 1.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohammadreza Rashidi
.