This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Jun 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mooveagency
Mooveagency user Activity Tracking And Log |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:mooveagency:user_activity_tracking_and_log:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Mooveagency
Mooveagency user Activity Tracking And Log |
Fri, 16 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. | |
Title | User Activity Tracking and Log < 4.1.4 - IP Spoofing | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-05-15T20:09:32.658Z
Updated: 2025-05-16T16:37:55.472Z
Reserved: 2024-01-26T19:42:29.765Z
Link: CVE-2024-0970

Updated: 2025-05-16T16:37:43.404Z

Status : Analyzed
Published: 2025-05-15T20:15:32.200
Modified: 2025-06-09T18:24:48.597
Link: CVE-2024-0970

No data.