CVE-2024-0970: User Activity Tracking and Log < 4.1.4 - IP Spoofing

7.5 CVSS

Description

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.

Classification

CVE ID: CVE-2024-0970

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem Types

CWE-290 Authentication Bypass by Spoofing

Affected Products

Vendor: Unknown

Product: User Activity Tracking and Log

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.1% (probability of being exploited)

EPSS Percentile: 27.73% (scored less or equal to compared to others)

EPSS Date: 2025-06-06 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-0970
https://wpscan.com/vulnerability/7df6877c-6640-41be-aacb-20c7da61e4db/

Timeline