CVE-2022-4746: FluentAuth < 1.0.2 - Bypass blocks by IP Spoofing
Published Jan 23, 2023
·Updated
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTEADDR, which makes it possible to bypass the IP-based blocks set by the plugin.
Affected Software
1 affected component
WPManageNinja Fluentauth Wordpress<1.0.2
Event History
Jan 23, 2023
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-4746?
CVE-2022-4746 is rated as a medium severity vulnerability due to its impact on IP-based access controls.
2
How do I fix CVE-2022-4746?
To fix CVE-2022-4746, update the FluentAuth WordPress plugin to version 1.0.2 or later.
3
What systems are affected by CVE-2022-4746?
CVE-2022-4746 affects the FluentAuth WordPress plugin versions prior to 1.0.2.
4
What is the exploit mechanism for CVE-2022-4746?
CVE-2022-4746 allows attackers to bypass IP-based blocks by prioritizing certain HTTP headers over the REMOTE_ADDR PHP variable.
5
Who is at risk from CVE-2022-4746?
Websites utilizing the outdated FluentAuth WordPress plugin are at risk from CVE-2022-4746.