CVE Vulnerabilities

CVE-2024-0970

Published: May 15, 2025 | Modified: Nov 13, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.

Affected Software

NameVendorStart VersionEnd Version
User_activity_tracking_and_logMooveagency*4.1.4 (excluding)

References