User Activity Log Pro <= 2.3.3 - Tracking Bypass via IP Spoofing
2023-09-25 00:00
Bartłomiej MarekStrategic Overview
StatusPatched in 2.3.4
Affected PluginUser Activity Log Pro
Affected Version
<= 2.3.3CVSS5.3Medium
CVE
CVE-2023-5133Vulnerability Overview
The User Activity Log Pro plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.3 due to insufficient IP address validation. This makes it possible for attackers to perform actions that are attributed to IP values that they control, rather than to the correct IP.
Technical Analysis
REMEDIATION: Update to version 2.3.4, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C