CVE-2022-4537
Last modified
CVE-2022-4537 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address from logging in.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpplugins | Hide My Wp Ghost | <= 5.0.18 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4537?
How severe is CVE-2022-4537?
How do I fix CVE-2022-4537?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-45364Cross-Site Request Forgery (CSRF) vulnerability in Glen Don …8.8
- CVE-2022-45365Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2022-45366Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2022-45367Cross-Site Request Forgery (CSRF) vulnerability in Tyche Sof…8.8
- CVE-2022-45368Improper Limitation of a Pathname to a Restricted Directory …7.7
- CVE-2022-45369Auth. (subscriber+) Broken Access Control vulnerability in P…4.3
- CVE-2022-45370Improper Neutralization of Formula Elements in a CSV File vu…9.8
- CVE-2022-45371Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Sho…8.8
- CVE-2022-45372Cross-Site Request Forgery (CSRF) vulnerability in Codeixer …8.8
- CVE-2022-45373Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2022-45374Improper Limitation of a Pathname to a Restricted Directory …6.5
- CVE-2022-45375Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulne…5.4
Are you affected by CVE-2022-4537?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
