9.1
CVE-2024-3050
- EPSS 0.76%
- Veröffentlicht 29.05.2024 06:18:32
- Zuletzt bearbeitet 21.05.2025 19:05:52
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Site Reviews <= 6.11.8 - IP Address Spoofing to Blocking Bypass
The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking
Mögliche Gegenmaßnahme
Site Reviews: Update to version 7.0.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Site Reviews
Version
*-6.11.8
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Geminilabs ≫ Site Reviews SwPlatformwordpress Version < 7.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.76% | 0.725 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|