cleantalk
Vulnerabilities and Security Researches

User Activity Log, CVE-2023-4279

CVE, Research URL

CVE-2023-4279

Application

User Activity Log

Published on
Sep 04, 2023
Research Description
This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.
Affected versions
max 1.6.7.
Status
vulnerable