{
 "id": "WPSEC-2026-0480",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0480/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0480/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0480/index.md",
 "title": "User Activity Tracking and Log <= 4.3.1 - Unauthenticated IP Address Spoofing via Client-IP Header",
 "description": "The User Activity Tracking and Log plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.3.1. The plugin trusts the client-supplied Client-IP (HTTP_CLIENT_IP) header by default when determining a visitor's IP address. This results from an incomplete fix for CVE-2024-0970: version 4.1.4 made the X-Forwarded-For header opt-in but continued to honour Client-IP unconditionally. This makes it possible for unauthenticated attackers to have an arbitrary IP address, and the location derived from it, recorded in the activity log in place of their real address, which undermines the integrity of the log. The plugin does not use this address for any access control, blocking or rate-limiting decision.",
 "plugin": {
  "slug": "user-activity-tracking-and-log",
  "name": "User Activity Tracking and Log",
  "full_name": "User Activity Tracking and Log",
  "wordpress_org": "https://wordpress.org/plugins/user-activity-tracking-and-log/",
  "advisories_url": "https://wpsec.com/vuln/plugin/user-activity-tracking-and-log/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/user-activity-tracking-and-log"
 },
 "type": "UNKNOWN",
 "cwe": [
  "CWE-348"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.3.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.3.2"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.3.2",
 "remediation": "Update to 4.3.2 or later.",
 "fix_released": "2026-10-05T12:10:05+00:00",
 "published": "2026-10-06T20:46:35+00:00",
 "updated": "2026-10-06T19:48:14.021599+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0480/",
  "https://plugins.svn.wordpress.org/user-activity-tracking-and-log/tags/4.3.2/",
  "https://wordpress.org/plugins/user-activity-tracking-and-log/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/user-activity-tracking-and-log",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-06"
 }
}