CVE Database /
CVE-2022-4537
CVE · Medium
CVE-2022-4537 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.20
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-4537
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.20 |
Insufficient Verification of Data Authenticity |
Medium
6.5
|
< 5.0.20
|
5.0.20 |
2023-05-08 |
—
|
CVE-2022-4537
The Hide My WP Ghost – Security Plugin for WordPress through version 5.0.18 contains an IP address spoofing vulnerability stemming from inadequate validation of IP sources during request logging and login restriction enforcement. Attackers can manipulate the X-Forwarded-For header to spoof their IP address, which the plugin then logs and uses for access control decisions, allowing them to circumvent IP-based login blocks that administrators have configured.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings