# User Activity Tracking and Log <= 4.3.1 - Unauthenticated IP Address Spoofing via Client-IP Header

- **ID:** WPSEC-2026-0480
- **Plugin:** User Activity Tracking and Log (`user-activity-tracking-and-log`), https://wordpress.org/plugins/user-activity-tracking-and-log/
- **Affected versions:** all versions before 4.3.2
- **Fixed in:** 4.3.2 (Update to 4.3.2 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-348
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/user-activity-tracking-and-log
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0480/

## Description

The User Activity Tracking and Log plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 4.3.1. The plugin trusts the client-supplied Client-IP (HTTP_CLIENT_IP) header by default when determining a visitor's IP address. This results from an incomplete fix for CVE-2024-0970: version 4.1.4 made the X-Forwarded-For header opt-in but continued to honour Client-IP unconditionally. This makes it possible for unauthenticated attackers to have an arbitrary IP address, and the location derived from it, recorded in the activity log in place of their real address, which undermines the integrity of the log. The plugin does not use this address for any access control, blocking or rate-limiting decision.

## References

- https://wpsec.com/vuln/WPSEC-2026-0480/
- https://plugins.svn.wordpress.org/user-activity-tracking-and-log/tags/4.3.2/
- https://wordpress.org/plugins/user-activity-tracking-and-log/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0480/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
