The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking
Name | Vendor | Start Version | End Version |
---|---|---|---|
Site_reviews | Geminilabs | * | 7.0.0 (excluding) |