This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
User_activity_tracking_and_log | Mooveagency | * | 4.1.4 (excluding) |