Input validation vulnerability in FluentAuth – The Ultimate Authorization & Security Plugin for WordPress 1.0.1

The FluentAuth plugin for WordPress has a security vulnerability that allows attackers to change the IP address that is logged when they log in. This could let them bypass settings that were put in place to block certain IP addresses from accessing the website. The vulnerability affects versions up to and including 1.0.1 and is caused by not having enough restrictions on where the IP address information is taken from for logging and limiting access.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.