Skip to main content

Vendor/product archive

ip2location / country_blocker CVEs

Beta · best-effort

8 CVEs tagged to ip2location / country_blocker0 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-1361

Published Feb 22, 2025

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24731

Published Jan 24, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker ip2location-country-blocker…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37865

Published Jun 4, 2024

Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affe…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-32443

Published Apr 15, 2024

Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22294

Published Jan 24, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a throug…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-25108

Published Feb 7, 2022

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a log…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25096

Published Feb 7, 2022

The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25095

Published Feb 7, 2022

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1