Comments Like Dislike <= 1.2.2 - IP Spoofing
2024-02-12 00:00
Kévin Mosbahi (Mika)Strategic Overview
StatusPatched in 1.2.3
Affected PluginComments Like Dislike
Affected Version
<= 1.2.2CVSS4.3Medium
CVE
CVE-2024-25906Vulnerability Overview
The Comments Like Dislike plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.2.2 due to use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for authenticated attackers with subscriber privileges and above to bypass IP restrictions.
Technical Analysis
REMEDIATION: Update to version 1.2.3, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C