Site Reviews <= 6.11.8 - IP Address Spoofing to Blocking Bypass
2024-05-08 00:00
Maksymilian KubiakStrategic Overview
StatusPatched in 7.0.0
Affected PluginSite Reviews
Affected Version
<= 6.11.8CVSS5.3Medium
CVE
CVE-2024-3050Vulnerability Overview
The Site Reviews plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.11.8 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass IP based blocking.
Technical Analysis
REMEDIATION: Update to version 7.0.0, or a newer patched version --- IDENTIFIER: CWE-290 (Authentication Bypass by Spoofing) This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C