Vulnerabilities (CVE)

Filtered by vendor User Activity Project Subscribe
Filtered by product User Activity
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4550 1 User Activity Project 1 User Activity 2024-11-21 N/A 7.5 HIGH
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing