CVE-2022-4100
MEDIUMWP Cerber Security <9.4 - Auth Bypass
Title source: llmDescription
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP header to an IP Address that hasn't been blocked.
Scores
CVSS v3
5.3
EPSS
0.0008
EPSS Percentile
23.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-693
Status
published
Affected Products (1)
wpcerber/cerber_security_antispam_\&_malware_scan
< 9.5
Timeline
Published
Aug 31, 2024
Tracked Since
Feb 18, 2026