CVE-2022-4550

Publication date

2023-02-27 15:24:36

Family

WPScan

State

PUBLISHED

Description

The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing