CVE-2024-0868: DEV4PRESS Coreactivity
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value
Affected products
- DEV4PRESS Coreactivity: before 2.1 (fixed in 2.1)
Published 2024-04-17. Last modified 2026-06-17.