Vulnerability Description
The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cm-Wp | Titan Anti-Spam \& Security | < 7.3.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/f1af4267-3a43-4b88-a8b9-c1d5b2aa9d68ExploitThird Party Advisory
- https://wpscan.com/vulnerability/f1af4267-3a43-4b88-a8b9-c1d5b2aa9d68ExploitThird Party Advisory
FAQ
What is CVE-2022-2877?
CVE-2022-2877 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by sp...
How severe is CVE-2022-2877?
CVE-2022-2877 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2877?
Check the references section above for vendor advisories and patch information. Affected products include: Cm-Wp Titan Anti-Spam \& Security.