Input validation vulnerability in Security & Malware scan by CleanTalk 2.120

The Security & Malware scan by CleanTalk plugin for WordPress has a vulnerability in versions up to and including 2.120, which could allow attackers to bypass login restrictions. This vulnerability is caused by not having strong enough restrictions on where the IP Address information for the request log and login restrictions is coming from. Attackers can use the X-Forwarded-For header to provide a different IP Address which can be logged and used to bypass settings that would normally block an IP address from logging in.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.