CVE Vulnerabilities

CVE-2024-0970

Published: May 15, 2025 | Modified: Nov 13, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.

Affected Software

Name Vendor Start Version End Version
User_activity_tracking_and_log Mooveagency * 4.1.4 (excluding)

References