Vulnerability Description
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| User Activity Project | User Activity | <= 1.0.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/a1179959-2044-479f-a5ca-3c9ffc46d00eExploitThird Party Advisory
- https://wpscan.com/vulnerability/a1179959-2044-479f-a5ca-3c9ffc46d00eExploitThird Party Advisory
FAQ
What is CVE-2022-4550?
CVE-2022-4550 is a vulnerability with a CVSS score of 7.5 (HIGH). The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing
How severe is CVE-2022-4550?
CVE-2022-4550 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4550?
Check the references section above for vendor advisories and patch information. Affected products include: User Activity Project User Activity.