IP Address Spoofing Vulnerability in Brizy Page Builder Plugin for WordPress
CVE-2023-2897
3.7LOW
What is CVE-2023-2897?
The Brizy Page Builder plugin for WordPress presents a vulnerability characterized by IP Address Spoofing due to an implicit trust of user-supplied IP addresses from the 'X-Forwarded-For' HTTP header. This vulnerability impacts versions up to and including 2.4.18, permitting attackers to bypass maintenance mode protection by submitting a whitelisted IP address in the header. Consequently, this can result in unauthorized access to restricted functionalities and possible exposure of sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Brizy β Page Builder * <= 2.4.18