CVE-2024-35749
WordPress Under Construction / Maintenance Mode from Acurax plugin <= 2.6 - IP Bypass vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authentication Bypass.This issue affects Under Construction / Maintenance Mode from Acurax: from n/a through 2.6.
La vulnerabilidad de omisión de autenticación mediante suplantación de identidad en Acurax Under Construction / Maintenance Mode from Acurax permite la omisión de autenticación. Este problema afecta a Under Construction / Maintenance Mode from Acurax: desde n/a hasta 2.6.
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.6 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass controls.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-17 CVE Reserved
- 2024-06-06 CVE Published
- 2024-06-13 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-290: Authentication Bypass by Spoofing
- CWE-348: Use of Less Trusted Source
CAPEC
- CAPEC-115: Authentication Bypass
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Acurax Search vendor "Acurax" | Under Construction \/ Maintenance Mode Search vendor "Acurax" for product "Under Construction \/ Maintenance Mode" | <= 2.6 Search vendor "Acurax" for product "Under Construction \/ Maintenance Mode" and version " <= 2.6" | wordpress |
Affected
|