5.3
CVSSv3

CVE-2023-4631

Published: 25/09/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The DoLogin Security WordPress plugin prior to 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

Vulnerable Product Search on Vulmon Subscribe to Product

wpdo5ea dologin security

Github Repositories

Repository for CVE-2023-4631 vulnerability.

CVE ID: CVE-2023-4631 Vulnerability Type: IP Address Spoofing Description: The DoLogin Security plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 36 This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions Attackers can supply the X-Forwarded-For header