Web Application Firewall – website security [web-application-firewall] < 2.1.3 (closed)
unknown
[en] The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header...
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Aug 31, 2024
CVE-2022-4539 on NVD →
Web Application Firewall <= 2.1.2 - IP Address Spoofing to Protection Mechanism Bypass
medium
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with...
- CVSS:
- 5.3
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Aug 30, 2024
CVE-2022-4539 on NVD →
Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
critical
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This m...
- CVSS:
- 9.8
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Mar 13, 2024
CVE-2024-2172 on NVD →
Web Application Firewall – website security [web-application-firewall] < 2.1.2 (closed)
unknown
[en] The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). T...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Mar 13, 2024
CVE-2024-2172 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database