CVE-2022-4534

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 459

Summary

CVE-2022-4534 is a vulnerability affecting the Limit Login Attempts (Spam Protection) plugin for WordPress. This issue allows attackers to spoof IP addresses by supplying a false address in the X-Forwarded-For header. As a result, the plugin logs and uses the fraudulent IP address for login restrictions, enabling attackers to bypass IP address or country blocking. Versions up to and including 5.3 of the plugin are vulnerable to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share