Back

HIGH

User Activity <= 1.0.1 - IP Spoofing

Published Feb 27, 2023

Description

The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Feb 27, 2023
Updated Mar 18, 2025
Reserved Dec 16, 2022
CISA Vulnrichment
Updated Mar 10, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a