Lucene search

K
wpvulndbWpvulndbWPVDB-ID:195DE3B7-D1D9-4FD2-804D-33A87F72E2EA
HistoryDec 07, 2023 - 12:00 a.m.

Antispam Bee < 2.11.4 - IP Address Spoofing via get_client_ip

2023-12-0700:00:00
wpscan.com
3
wordpress
antispam bee
vulnerability
ip address spoofing
http headers

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The Antispam Bee plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.11.3 due to use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass country blocking.

CPENameOperatorVersion
eq2.11.4

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:195DE3B7-D1D9-4FD2-804D-33A87F72E2EA