CVE-2024-13685

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wpase:admin_and_site_enhancements:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:wpase:admin_and_site_enhancements:*:*:*:*:pro:wordpress:*:*

History

No history.

Information

Published : 2025-03-04 06:15

Updated : 2025-05-14 14:51


NVD link : CVE-2024-13685

Mitre link : CVE-2024-13685

CVE.ORG link : CVE-2024-13685


JSON object : View

Products Affected

wpase

  • admin_and_site_enhancements
CWE
CWE-290

Authentication Bypass by Spoofing