Lucene search

K
wpvulndbDaniel RufWPVDB-ID:15819D33-7497-4F7D-BBB8-B3AB147806C4
HistoryNov 21, 2022 - 12:00 a.m.

All In One WP Security & Firewall < 5.0.8 - IP Spoofing

2022-11-2100:00:00
Daniel Ruf
wpscan.com
6
wordpress
security plugin
ip spoofing

EPSS

0.001

Percentile

33.3%

The plugin is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more).

PoC

Set HTTP_X_REAL_IP or HTTP_X_FORWARDED_FOR used in get_user_ip_address() to bypass IP-based blocks.

EPSS

0.001

Percentile

33.3%

Related for WPVDB-ID:15819D33-7497-4F7D-BBB8-B3AB147806C4