User Activity Tracking and Log <= 4.3.1 - Unauthenticated IP Address Spoofing via Client-IP Header

Medium 5.3 CWE-348Fixed in 4.3.2
ID
WPSEC-2026-0480
Plugin
User Activity Tracking and Log (user-activity-tracking-and-log)
Affected
all versions before 4.3.2
Remediation
Update to 4.3.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-348
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
User Activity Tracking and Log on WPSec AttackSurface
Fix released
Published

Description

The User Activity Tracking and Log plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.3.1. The plugin trusts the client-supplied Client-IP (HTTP_CLIENT_IP) header by default when determining a visitor's IP address. This results from an incomplete fix for CVE-2024-0970: version 4.1.4 made the X-Forwarded-For header opt-in but continued to honour Client-IP unconditionally. This makes it possible for unauthenticated attackers to have an arbitrary IP address, and the location derived from it, recorded in the activity log in place of their real address, which undermines the integrity of the log. The plugin does not use this address for any access control, blocking or rate-limiting decision.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0