Ip2location
Ip2location Country Blocker: vulnerabilidades y CVE
Ip2location Country Blocker tiene 12 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82530 | Media (6.9) | 0.44% | — | 9 sept 2026 | IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP… |
| CVE-2022-50961 | Media (5.1) | 0.19% | — | 10 may 2026 | WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface.… |
| CVE-2025-1361 | Media (5.3) | 1.3% | — | 22 feb 2025 | The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes… |
| CVE-2025-24731 | Media (4.8) | 0.31% | — | 24 ene 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker ip2location-country-blocker allows Stored XSS.This issue affects… |
| CVE-2024-11459 | Media (6.1) | 0.39% | — | 12 dic 2024 | The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-54226 | Alta (7.1) | 0.20% | — | 9 dic 2024 | Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker: from n/a through <= 3.2. |
| CVE-2023-37865 | Media (5.3) | 0.42% | — | 4 jun 2024 | Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country… |
| CVE-2024-32443 | Alta (8.8) | 0.24% | — | 15 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2. |
| CVE-2024-22294 | Alta (7.5) | 0.45% | — | 24 ene 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3. |
| CVE-2021-25108 | Alta (7.1) | 0.45% | — | 7 feb 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or… |
| CVE-2021-25096 | Media (6.5) | 1.0% | — | 7 feb 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL |
| CVE-2021-25095 | Alta (7.1) | 0.54% | — | 7 feb 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber… |