PT-2023-14171 · WordPress+1 · Wp Limit Login Attempts+1

Daniel Ruf

·

Published

2023-01-23

·

Updated

2024-04-17

·

CVE-2022-4303

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WP Limit Login Attempts plugin versions prior to 2.7
Description The issue allows bypassing IP-based restrictions on login forms by prioritizing certain HTTP headers over PHP's REMOTE ADDR for getting a visitor's IP.
Recommendations For WP Limit Login Attempts plugin versions prior to 2.7, update to version 2.7 or later to resolve the issue.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

ALT-PU-2024-2511
ALT-PU-2024-6382
CVE-2022-4303

Affected Products

Alt Linux
Wp Limit Login Attempts