### [CVE-2014-6230](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6230) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header. ### POC #### Reference - http://seclists.org/fulldisclosure/2014/Sep/60 - https://security.dxw.com/advisories/vulnerability-in-wp-ban-allows-visitors-to-bypass-the-ip-blacklist-in-some-configurations/ #### Github - https://github.com/Live-Hack-CVE/CVE-2014-6230 - https://github.com/lesterchan/wp-ban