The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/a1179959-2044-479f-a5ca-3c9ffc46d00e | exploit vdb entry third party advisory technical description |