### [CVE-2024-3050](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3050) ![](https://img.shields.io/static/v1?label=Product&message=Site%20Reviews&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%207.0.0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-290%20Authentication%20Bypass%20by%20Spoofing&color=brighgreen) ### Description The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking ### POC #### Reference - https://wpscan.com/vulnerability/04c1581e-fd36-49d4-8463-b49915d4b1ac/ #### Github - https://github.com/DojoSecurity/DojoSecurity - https://github.com/afine-com/research - https://github.com/vemusx/vemusx