CVE-2024-0970: Mooveagency User Activity Tracking And Log

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.

Affected products

  • Mooveagency User Activity Tracking And Log: before 4.1.4 (fixed in 4.1.4)

Published 2025-05-15. Last modified 2026-06-17.