Lucene search

K
wpvulndbDaniel RufWPVDB-ID:62E3BABC-00C6-4A35-972F-8F03BA70BA32
HistoryDec 27, 2022 - 12:00 a.m.

FluentAuth < 1.0.2 - Bypass blocks by IP Spoofing

2022-12-2700:00:00
Daniel Ruf
wpscan.com
14
fluentauth
plugin
ip spoofing
bypass
http headers
php
remote_addr

0.001 Low

EPSS

Percentile

32.1%

The plugin prioritizes getting a visitor’s IP address from certain HTTP headers over PHP’s REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.

PoC

Set HTTP_X_REAL_IP, HTTP_X_FORWARDED_FOR, HTTP_CF_CONNECTING_IP or HTTP_CLIENT_IP to spoof the IP address.

CPENameOperatorVersion
fluent-securitylt1.0.2

0.001 Low

EPSS

Percentile

32.1%

Related for WPVDB-ID:62E3BABC-00C6-4A35-972F-8F03BA70BA32