CVE Vulnerabilities

CVE-2024-0970

Published: May 15, 2025 | Modified: Jun 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.

Affected Software

Name Vendor Start Version End Version
User_activity_tracking_and_log Mooveagency * 4.1.4 (excluding)

References