CVE-2023-4631: Wpdo Dologin Security

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

Affected products

  • Wpdo Dologin Security: before 3.7 (fixed in 3.7)

Published 2023-09-25. Last modified 2026-06-17.