Vulnerabilities > Wpmanageninja > Fluentauth > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-23 CVE-2022-4746 Authentication Bypass by Spoofing vulnerability in Wpmanageninja Fluentauth
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.
network
low complexity
wpmanageninja CWE-290
7.5