User Activity Tracking and Log <= 4.3.1 - Unauthenticated IP Address Spoofing via Client-IP Header
- ID
- WPSEC-2026-0480
- Plugin
- User Activity Tracking and Log (user-activity-tracking-and-log)
- Affected
- all versions before 4.3.2
- Remediation
- Update to 4.3.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-348
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- User Activity Tracking and Log on WPSec AttackSurface
- Fix released
- Published
Description
The User Activity Tracking and Log plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.3.1. The plugin trusts the client-supplied Client-IP (HTTP_CLIENT_IP) header by default when determining a visitor's IP address. This results from an incomplete fix for CVE-2024-0970: version 4.1.4 made the X-Forwarded-For header opt-in but continued to honour Client-IP unconditionally. This makes it possible for unauthenticated attackers to have an arbitrary IP address, and the location derived from it, recorded in the activity log in place of their real address, which undermines the integrity of the log. The plugin does not use this address for any access control, blocking or rate-limiting decision.
References
- https://wpsec.com/vuln/WPSEC-2026-0480/
- https://plugins.svn.wordpress.org/user-activity-tracking-and-log/tags/4.3.2/
- https://wordpress.org/plugins/user-activity-tracking-and-log/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS