Input validation vulnerability in coreActivity: Activity Logging plugin for WordPress 2.0.1

The Activity Logging plugin for WordPress is at risk of IP Address Spoofing, which means that someone could pretend to have a different IP address than they actually do. This vulnerability exists in all versions of the plugin up to and including 2.0.1. It is caused by not properly checking IP addresses and relying too heavily on user-provided information. As a result, hackers without authentication could trick the system into thinking they have a different IP address than they actually do.

Detected in:

coreActivity: Activity Logging plugin for WordPress fixed vulnerable versions: >= * <= 2.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.