Antispam Bee <= 2.11.3 - IP Address Spoofing via get_client_ip
2023-11-27 00:00
Kévin Mosbahi (Mika)Strategic Overview
StatusPatched in 2.11.4
Affected PluginAntispam Bee
Affected Version
<= 2.11.3CVSS5.3Medium
CVE
CVE-2023-41134Vulnerability Overview
The Antispam Bee plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.11.3 due to use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass country blocking.
Technical Analysis
REMEDIATION: Update to version 2.11.4, or a newer patched version --- IDENTIFIER: CWE-807 (Reliance on Untrusted Inputs in a Security Decision) The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C