HomeDefault status
unaffected
Any version before 4.1.4
affected
Description
This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.
Problem types
CWE-290 Authentication Bypass by Spoofing
Product status
Any version before 4.1.4
Credits
Dmitrii Ignatyev
WPScan
References
wpscan.com/...rability/7df6877c-6640-41be-aacb-20c7da61e4db/