Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78296 2 Wordpress, Wpmanageninja 2 Wordpress, Fluentauth 2026-09-18 5.3 Medium
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.
CVE-2022-4746 1 Wpmanageninja 1 Fluentauth 2025-04-02 7.5 High
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.