Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m748-r53c-f6pp

Опубликовано: 31 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP header to an IP Address that hasn't been blocked.

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP header to an IP Address that hasn't been blocked.

EPSS

Процентиль: 24%
0.0008
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP header to an IP Address that hasn't been blocked.

EPSS

Процентиль: 24%
0.0008
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-693