Antispam Bee <= 2.11.3 - IP Address Spoofing via get_client_ip
mediumThe Antispam Bee plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.11.3 due to use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass country blocking.
- CVSS:
- 5.3
- Affected:
- up to 2.11.3
- Fixed in:
- 2.11.4
- Disclosed:
- Nov 27, 2023