CVE-2024-0970

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mooveagency:user_activity_tracking_and_log:*:*:*:*:*:wordpress:*:*

History

09 Jun 2025, 18:24

Type Values Removed Values Added
CPE cpe:2.3:a:mooveagency:user_activity_tracking_and_log:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/7df6877c-6640-41be-aacb-20c7da61e4db/ - () https://wpscan.com/vulnerability/7df6877c-6640-41be-aacb-20c7da61e4db/ - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo
First Time Mooveagency
Mooveagency user Activity Tracking And Log

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-09 18:24


NVD link : CVE-2024-0970

Mitre link : CVE-2024-0970


JSON object : View

Products Affected

mooveagency

  • user_activity_tracking_and_log