CVE-2024-0868

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/04/2024
Last modified:
17/06/2025

Description

The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dev4press:coreactivity:*:*:*:*:*:wordpress:*:* 2.1 (excluding)