CVE-2022-4534
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 459
Summary
CVE-2022-4534 is a vulnerability affecting the Limit Login Attempts (Spam Protection) plugin for WordPress. This issue allows attackers to spoof IP addresses by supplying a false address in the X-Forwarded-For header. As a result, the plugin logs and uses the fraudulent IP address for login restrictions, enabling attackers to bypass IP address or country blocking. Versions up to and including 5.3 of the plugin are vulnerable to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Apache Software Foundation