CVE-2014-6230 Information

Description

WP-Ban plugin before 1.6.4 for WordPress when running in certain configurations allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.

Reference

http://seclists.org/fulldisclosure/2014/Sep/60 https://security.dxw.com/advisories/vulnerability-in-wp-ban-allows-visitors-to-bypass-the-ip-blacklist-in-some-configurations/ https://wordpress.org/plugins/wp-ban/changelog/

Share on: