CVE-2024-0970

Publication date

2025-05-15 20:09:32

Family

WPScan

State

PUBLISHED

Description

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.