WP Cerber Security <= 9.4 - IP Protection Bypass
2024-08-30 00:00
chihyuStrategic Overview
StatusPatched in 9.5
Affected PluginWP Cerber Security, Anti-spam & Malware Scan
Affected Version
<= 9.4CVSS5.3Medium
CVE
CVE-2022-4100Vulnerability Overview
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP header to an IP Address that hasn't been blocked.
Technical Analysis
REMEDIATION: Update to version 9.5, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C