CVE-2022-4303: WP Limit Login Attempts <= 2.6.4 - IP Spoofing
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTEADDR, which makes it possible to bypass IP-based restrictions on login forms.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-4303.
What is the severity of CVE-2022-4303?
The severity of CVE-2022-4303 is high with a CVSS score of 7.5.
What is the affected software for CVE-2022-4303?
The affected software for CVE-2022-4303 is the WP Limit Login Attempts WordPress plugin up to and including version 2.6.4.
How does CVE-2022-4303 allow bypassing IP-based restrictions on login forms?
CVE-2022-4303 allows bypassing IP-based restrictions on login forms by prioritizing getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR.
Is there a fix available for CVE-2022-4303?
At the time of writing, there is no known fix available for CVE-2022-4303. It is recommended to monitor the vendor's website for any updates or patches.