{"id":"CVE-2022-4746","details":"The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.","modified":"2026-03-14T12:00:33.463332Z","published":"2023-01-23T15:15:17.303Z","references":[{"type":"EVIDENCE","url":"https://wpscan.com/vulnerability/62e3babc-00c6-4a35-972f-8f03ba70ba32"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wpmanageninja/fluent-auth","events":[{"introduced":"0"},{"fixed":"764f144f8f22b1c660c37d6aade8d6f094823c9a"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.0.2"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4746.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}