Lucene search

K
cvelistWPScanCVELIST:CVE-2023-5239
HistoryNov 27, 2023 - 4:22 p.m.

CVE-2023-5239 Security & Malware scan by CleanTalk < 2.121 - IP Spoofing

2023-11-2716:22:00
WPScan
www.cve.org
security & malware scan
cleantalk plugin
ip spoofing
cve-2023-5239
wordpress
brute force protection

0.0005 Low

EPSS

Percentile

17.8%

The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Security & Malware scan by CleanTalk",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "2.121"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

0.0005 Low

EPSS

Percentile

17.8%

Related for CVELIST:CVE-2023-5239