CVE-2022-4011 is a critical vulnerability affecting the Simple History Plugin, specifically within its Header Handler component. By manipulating the X-Forwarded-For argument, attackers can achieve improper output neutralization in logs, leading to potential remote code execution, data compromise, and denial of service. With a CVSS score of 9.8, this vulnerability is easily exploitable remotely without user interaction. While public exploit disclosure exists, there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:simple_history_project:simple_history:-:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.