IP Address Spoofing Vulnerability in WP Firewall Plugin
CVE-2022-4536
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 31 August 2024
Summary
The WP Firewall plugin for WordPress is affected by a vulnerability that permits IP Address Spoofing in versions up to and including 1.1. This issue arises from inadequate restrictions on the sources from which IP Address information is fetched for request logging and login restrictions. Malicious actors can exploit this flaw by providing a maliciously crafted X-Forwarded-For header, which allows them to log in with an IP address that may have been previously blocked. As a result, normal security measures that deny access to specific IP addresses or geographic locations can be circumvented, potentially leading to unauthorized access and further exploitation.
Affected Version(s)
Two-factor authentication (formerly IP Vault) * <= 1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved