Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-4539 — Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable payload and IP-generation logic for targeted security testing. | Kitploit
Tools/GitHubGitHub/abdurahmon3236/cve-2022-4539
IDS/IPS EvasionImpersonation ToolsWeb Application ExploitationWAF BypassPenetration TestingFingerprint Spoofing
GitHubabdurahmon3236/cve-2022-4539

CVE-2022-4539

Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable payload and IP-generation logic for targeted security testing.

View Repository
62 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Usage Considerations:

  • Adaptability: You can easily modify the payloads, IP generation logic, and proxies to match different scenarios or environments.
  • Ethical Use: Ensure you have explicit permission before testing any system with this code.
  • Scalability: This code is designed to be scalable and adaptable, making it suitable for both small-scale testing and larger, more sophisticated assessments.

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.

Download Tool