LionScripts: IP Blocker Lite [ip-address-blocker] <= 11.1.1 (unfixed + closed)
unknown
[en] Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.
- Affected:
- up to 11.1.1
- Fix:
- No patched version reported
- Disclosed:
- May 17, 2024
CVE-2024-30479 on NVD →
IP Blocker Lite <= 11.1.1 - IP Spoofing
medium
The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 11.1.1 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP Address and bypass blocklisting.
- CVSS:
- 5.3
- Affected:
- up to 11.1.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 28, 2024
CVE-2024-30479 on NVD →
LionScripts: IP Blocker Lite [ip-address-blocker] <= 11.1.1 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions.
- Affected:
- up to 11.1.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 10, 2023
CVE-2023-23993 on NVD →
IP Blocker Lite <= 11.1.1 - Cross-Site Request Forgery
medium
The IP Blocker Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.1.1. This is due to missing or incorrect nonce validation on the save_configuration, delete_ip, and add_ip_to_db functions. This makes it possible for unauthenticated attackers to enable or disable...
- CVSS:
- 5.4
- Affected:
- up to 11.1.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 28, 2023
CVE-2023-23993 on NVD →
LionScripts: IP Blocker Lite [ip-address-blocker] < 10.5 (closed)
unknown
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability found in WordPress IP Address Blocker plugin (versions <= 10.3).
- Affected:
- up to 10.5
- Fixed in:
- 10.5
- Disclosed:
- Jun 19, 2019
LionScripts: IP Blocker Lite <= 10.4 - Cross-Site Request Forgery to Arbitrary File Upload
high
The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to arbitrary file uploads via Cross-Site Request Forgery due to missing nonce verification and file type validation in the ip-address-blocker/trunk/lib/lionscripts_plg_wib.class.php file in versions up to, and including, 10.4. This makes it possible fo...
- CVSS:
- 8.8
- Affected:
- up to 10.4
- Fixed in:
- 10.5
- Disclosed:
- Jun 15, 2019
LionScripts: IP Blocker Lite [ip-address-blocker] < 10.5 (closed)
unknown
The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to arbitrary file uploads via Cross-Site Request Forgery due to missing nonce verification and file type validation in the ip-address-blocker/trunk/lib/lionscripts_plg_wib.class.php file in versions up to, and including, 10.4. This makes it possible fo...
- Affected:
- up to 10.5
- Fixed in:
- 10.5
- Disclosed:
- Jun 15, 2019
LionScripts: IP Blocker Lite [ip-address-blocker] < 10.5 (closed)
unknown
The LionScripts: IP Blocker Lite WordPress plugin was affected by a CSRF leading to Arbitrary File Upload security vulnerability.
- Affected:
- up to 10.5
- Fixed in:
- 10.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database