CVE-2022-4539
Last modified
CVE-2022-4539 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Miniorange | Web Application Firewall | < 2.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-4539?
How severe is CVE-2022-4539?
How do I fix CVE-2022-4539?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-45384Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores t…6.5
- CVE-2022-45385A missing permission check in Jenkins CloudBees Docker Hub/R…7.5
- CVE-2022-45386Jenkins Violations Plugin 0.7.11 and earlier does not config…5.5
- CVE-2022-45387Jenkins BART Plugin 1.0.3 and earlier does not escape the pa…5.4
- CVE-2022-45388Jenkins Config Rotator Plugin 2.0.1 and earlier does not res…7.5
- CVE-2022-45389A missing permission check in Jenkins XP-Dev Plugin 1.0 and …5.3
- CVE-2022-45390A missing permission check in Jenkins loader.io Plugin 1.0.1…4.3
- CVE-2022-45391Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0…7.5
- CVE-2022-45392Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0…6.5
- CVE-2022-45393A cross-site request forgery (CSRF) vulnerability in Jenkins…3.5
- CVE-2022-45394A missing permission check in Jenkins Delete log Plugin 1.0 …4.3
- CVE-2022-45395Jenkins CCCC Plugin 0.6 and earlier does not configure its X…9.8
Are you affected by CVE-2022-4539?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
