User Activity Tracking and Log WordPress Plugin IP Spoofing Vulnerability

Vulnerability

A vulnerability exists in the User Activity Tracking and Log WordPress plugin in versions prior to 4.1.4. The issue arises because the plugin retrieves client IP addresses from potentially untrusted headers, allowing attackers to manipulate the IP values.

Impact

Exploitation of this vulnerability could lead to IP address spoofing, allowing attackers to impersonate other users or systems.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.