Vulnerability Description
The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dev4Press | Coreactivity | < 2.1 |
References
- https://wpscan.com/vulnerability/bb7c2d2b-cdfe-433b-96cf-714e71d12b22/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/bb7c2d2b-cdfe-433b-96cf-714e71d12b22/ExploitThird Party Advisory
FAQ
What is CVE-2024-0868?
CVE-2024-0868 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbi...
How severe is CVE-2024-0868?
CVE-2024-0868 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0868?
Check the references section above for vendor advisories and patch information. Affected products include: Dev4Press Coreactivity.