Vulnerabilities > Ip2Location > Country Blocker > 2.26.5

DATE CVE VULNERABILITY TITLE RISK
2025-02-22 CVE-2025-1361 Improper Authorization vulnerability in Ip2Location Country Blocker
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function.
network
low complexity
ip2location CWE-285
5.3
2024-04-15 CVE-2024-32443 Unspecified vulnerability in Ip2Location Country Blocker
Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2.
network
low complexity
ip2location
8.8
2024-01-24 CVE-2024-22294 Unspecified vulnerability in Ip2Location Country Blocker
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3.
network
low complexity
ip2location
7.5
2022-02-07 CVE-2021-25108 Cross-Site Request Forgery (CSRF) vulnerability in Ip2Location Country Blocker
The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
network
low complexity
ip2location CWE-352
7.1