Vulnerability CVE-2022-4303: Information

Description

The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Published: Jan. 23, 2023
Modified: Nov. 7, 2023
Error type identifier: CWE-290

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
python3p103.9.18-alt13.9.18-alt1ALT-PU-2024-2511-3340781Fixed
python3p10_e2k3.9.18-alt13.9.18-alt1ALT-PU-2024-3765-1-Fixed
python3c10f13.9.18-alt0.c10f1.13.9.18-alt0.c10f1.1ALT-PU-2024-6382-3344932Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:ciphercoin:wp_limit_login_attempts:*:*:*:*:*:wordpress:*:*
      End including
      2.6.4