Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3728ADFC-25A5-4C16-80A6-FB20E1D28252
HistoryDec 07, 2023 - 12:00 a.m.

Coming soon and Maintenance mode <= 3.7.3 - IP Address Spoofing via get_real_ip

2023-12-0700:00:00
wpscan.com
3
wordpress
plugin
vulnerability
ip address spoofing
http headers

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The Coming soon and Maintenance mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.7.3 due to the use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for attackers to bypass the coming soon mode page and visit the full site by spoofing an allowed IP.

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:3728ADFC-25A5-4C16-80A6-FB20E1D28252