cleantalk
Vulnerabilities and Security Researches

DoLogin Security, 0ce96febe7b9755fbb1e0e6afd5664058b92248c

Application

DoLogin Security

Published on
Aug 21, 2023
Research Description
DoLogin Security [dologin] < 3.7 DoLogin Security <= 3.6 - IP Address Spoofing The DoLogin Security plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 3.6. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address from logging in.
Affected versions
max 3.7.
Status
vulnerable