Vulnerabilities > Ip2Location

DATE CVE VULNERABILITY TITLE RISK
2024-01-24 CVE-2024-22294 Information Exposure vulnerability in Ip2Location Country Blocker
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3.
network
low complexity
ip2location CWE-200
7.5
2022-02-07 CVE-2021-25095 Missing Authorization vulnerability in Ip2Location Country Blocker
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
network
low complexity
ip2location CWE-862
7.1
2022-02-07 CVE-2021-25096 Authorization Bypass Through User-Controlled Key vulnerability in Ip2Location Country Blocker
The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL
network
low complexity
ip2location CWE-639
6.4
2022-02-07 CVE-2021-25108 Cross-Site Request Forgery (CSRF) vulnerability in Ip2Location Country Blocker
The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
5.8