CVE-2022-1601

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Aug 30, 2023
Updated: Nov 7, 2023

Summary

CVE-2022-1601 is a vulnerability affecting the User Access Manager plugin for WordPress. This issue allows attackers to bypass access controls by manipulating specific HTTP headers to mask their IP address, which is prioritized over the one detected by PHP's REMOTE_ADDR. As a result, unauthorized users may gain access to restricted content in certain scenarios. WordPress users are encouraged to update the User Access Manager plugin to version 2.2.18 to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share