CVE-2024-3050
The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking
- Affected products
- Site Reviews
- Geminilabs Site Reviews
- < 7.0.0
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.6% (44th percentile)
- NVD status
- Analyzed
- Published
- 2024-05-29
CVE-2024-3050 at NVD
1 known exploit for CVE-2024-3050
Proof-of-concept code and exploit modules indexed by Sploitus