CVE-2024-25906

Comments Like Dislike <= 1.2.2 - IP Spoofing

2024-02-12 00:00
Kévin Mosbahi (Mika)

Strategic Overview

Status
Patched in 1.2.3
Affected Plugin
Comments Like Dislike
Affected Version
<= 1.2.2
CVSS
4.3Medium
Weakness type
CWE-693 · Protection Mechanism Failure
CVE
CVE-2024-25906
View all Comments Like Dislike vulnerabilities

At a glance

CVE-2024-25906 is a medium-severity Protection Mechanism Failure vulnerability in the Comments Like Dislike WordPress plugin, affecting versions <= 1.2.2. It carries a CVSS score of 4.3 (reachable over the network; low attack complexity). The issue is fixed in version 1.2.3; sites on affected versions should update now. Disclosed February 2024, reported by Kévin Mosbahi (Mika).

Vulnerability Overview

The Comments Like Dislike plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.2.2 due to use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for authenticated attackers with subscriber privileges and above to bypass IP restrictions.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.

CWE-693: Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Remediation

Update to version 1.2.3, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: Comments Like Dislike 1.2.3 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C