CVE-2024-0868: DEV4PRESS Coreactivity

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value

Affected products

  • DEV4PRESS Coreactivity: before 2.1 (fixed in 2.1)

Published 2024-04-17. Last modified 2026-06-17.