← back
CVE-2022-1614CWE-639

WP-Email < 2.69.0 - Anti-Spam Protection Bypass via IP Spoofing

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
Affected products
Unknown · WP-EMail