plugin

Web Application Firewall Vulnerabilities

4 known security issues reported for the Web Application Firewall WordPress plugin. Most recent disclosed Aug 31, 2024.

1 critical 1 medium

Running Web Application Firewall on your site? Check whether your installed version is affected.

Scan your site free

Web Application Firewall &#8211; website security [web-application-firewall] < 2.1.3 (closed)

unknown

[en] The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Aug 31, 2024

CVE-2022-4539 on NVD →

Web Application Firewall <= 2.1.2 - IP Address Spoofing to Protection Mechanism Bypass

medium

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with...

CVSS:
5.3
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Aug 30, 2024

CVE-2022-4539 on NVD →

Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation

critical

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This m...

CVSS:
9.8
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Mar 13, 2024

CVE-2024-2172 on NVD →

Web Application Firewall &#8211; website security [web-application-firewall] < 2.1.2 (closed)

unknown

[en] The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). T...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Mar 13, 2024

CVE-2024-2172 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database