CVE-2022-4100

MEDIUM

WP Cerber Security <9.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP header to an IP Address that hasn't been blocked.

Scores

CVSS v3 5.3
EPSS 0.0035
EPSS Percentile 26.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-693
Status published
Products (2)
gioni/WP Cerber Security, Anti-spam & Malware Scan < 9.4
wpcerber/cerber_security_antispam_\&_malware_scan < 9.5
Published Aug 31, 2024
Tracked Since Feb 18, 2026