plugin

Ip Address Blocker Vulnerabilities

8 known security issues reported for the Ip Address Blocker WordPress plugin. Most recent disclosed May 17, 2024.

1 high 2 medium

Running Ip Address Blocker on your site? Check whether your installed version is affected.

Scan your site free

LionScripts: IP Blocker Lite [ip-address-blocker] <= 11.1.1 (unfixed + closed)

unknown

[en] Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.

Affected:
up to 11.1.1
Fix:
No patched version reported
Disclosed:
May 17, 2024

CVE-2024-30479 on NVD →

IP Blocker Lite <= 11.1.1 - IP Spoofing

medium

The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 11.1.1 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP Address and bypass blocklisting.

CVSS:
5.3
Affected:
up to 11.1.1
Fix:
No patched version reported
Disclosed:
Mar 28, 2024

CVE-2024-30479 on NVD →

LionScripts: IP Blocker Lite [ip-address-blocker] <= 11.1.1 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions.

Affected:
up to 11.1.1
Fix:
No patched version reported
Disclosed:
Jul 10, 2023

CVE-2023-23993 on NVD →

IP Blocker Lite <= 11.1.1 - Cross-Site Request Forgery

medium

The IP Blocker Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.1.1. This is due to missing or incorrect nonce validation on the save_configuration, delete_ip, and add_ip_to_db functions. This makes it possible for unauthenticated attackers to enable or disable...

CVSS:
5.4
Affected:
up to 11.1.1
Fix:
No patched version reported
Disclosed:
Mar 28, 2023

CVE-2023-23993 on NVD →

LionScripts: IP Blocker Lite [ip-address-blocker] < 10.5 (closed)

unknown

Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability found in WordPress IP Address Blocker plugin (versions <= 10.3).

Affected:
up to 10.5
Fixed in:
10.5
Disclosed:
Jun 19, 2019

LionScripts: IP Blocker Lite <= 10.4 - Cross-Site Request Forgery to Arbitrary File Upload

high

The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to arbitrary file uploads via Cross-Site Request Forgery due to missing nonce verification and file type validation in the ip-address-blocker/trunk/lib/lionscripts_plg_wib.class.php file in versions up to, and including, 10.4. This makes it possible fo...

CVSS:
8.8
Affected:
up to 10.4
Fixed in:
10.5
Disclosed:
Jun 15, 2019

LionScripts: IP Blocker Lite [ip-address-blocker] < 10.5 (closed)

unknown

The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to arbitrary file uploads via Cross-Site Request Forgery due to missing nonce verification and file type validation in the ip-address-blocker/trunk/lib/lionscripts_plg_wib.class.php file in versions up to, and including, 10.4. This makes it possible fo...

Affected:
up to 10.5
Fixed in:
10.5
Disclosed:
Jun 15, 2019

LionScripts: IP Blocker Lite [ip-address-blocker] < 10.5 (closed)

unknown

The LionScripts: IP Blocker Lite WordPress plugin was affected by a CSRF leading to Arbitrary File Upload security vulnerability.

Affected:
up to 10.5
Fixed in:
10.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database