CVE-2022-4746: Wpmanageninja Fluentauth
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.
Affected products
- Wpmanageninja Fluentauth: before 1.0.2 (fixed in 1.0.2)
Published 2023-01-23. Last modified 2026-06-17.