CVE-2024-0868 – coreActivity < 2.1 - Unauthenticated IP Spoofing
https://notcve.org/view.php?id=CVE-2024-0868
The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value El complemento coreActivity: Activity Logging plugin for WordPress anterior a 2.1 recuperaba direcciones IP de solicitudes a través de encabezados como X-FORWARDED para registrarlas, lo que permitía a los usuarios falsificarlas proporcionando un valor arbitrario. The coreActivity: Activity Logging plugin for WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.1 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to spoof their IP address. • https://wpscan.com/vulnerability/bb7c2d2b-cdfe-433b-96cf-714e71d12b22 • CWE-348: Use of Less Trusted Source •