plugin

Ip2Location Country Blocker Vulnerabilities

19 known security issues reported for the Ip2Location Country Blocker WordPress plugin. Most recent disclosed Feb 21, 2025.

3 high 6 medium

Running Ip2Location Country Blocker on your site? Check whether your installed version is affected.

Scan your site free

IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function

high

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVSS:
7.5
Affected:
up to 2.38.8
Fixed in:
2.38.9
Disclosed:
Feb 21, 2025

CVE-2025-1361 on NVD →

Download IP2Location Country Blocker <= 2.38.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Download IP2Location Country Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.38.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitra...

CVSS:
4.4
Affected:
up to 2.38.3
Fixed in:
2.38.4
Disclosed:
Jan 24, 2025

CVE-2025-24731 on NVD →

IP2Location Country Blocker [ip2location-country-blocker] < 2.38.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker allows Stored XSS. This issue affects Download IP2Location Country Blocker: from n/a through 2.38.3.

Affected:
up to 2.38.4
Fixed in:
2.38.4
Disclosed:
Jan 24, 2025

CVE-2025-24731 on NVD →

IP2Location Country Blocker [ip2location-country-blocker] < 2.29.2

unknown

[en] Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country Blocker: from n/a through 2.29.1.

Affected:
up to 2.29.2
Fixed in:
2.29.2
Disclosed:
Jun 4, 2024

CVE-2023-37865 on NVD →

IP2Location Country Blocker [ip2location-country-blocker] < 2.34.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2.

Affected:
up to 2.34.3
Fixed in:
2.34.3
Disclosed:
Apr 15, 2024

CVE-2024-32443 on NVD →

Download IP2Location Country Blocker <= 2.34.2 - Cross-Site Request Forgery

medium

The Download IP2Location Country Blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.34.2. This is due to missing or incorrect nonce validation on the validate_api_key() function. This makes it possible for unauthenticated attackers to replace the API key via a f...

CVSS:
4.3
Affected:
up to 2.34.2
Fixed in:
2.34.3
Disclosed:
Apr 12, 2024

CVE-2024-32443 on NVD →

IP2Location Country Blocker [ip2location-country-blocker] < 2.33.4

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3.

Affected:
up to 2.33.4
Fixed in:
2.33.4
Disclosed:
Jan 24, 2024

CVE-2024-22294 on NVD →

IP2Location Country Blocker <= 2.33.3 - Unauthenticated Sensitive Information Exposure via Debug Log File

medium

The IP2Location Country Blocker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.3 via ip2location-country-blocker.php. This makes it possible for unauthenticated attackers to extract sensitive data including debug information.

CVSS:
5.3
Affected:
up to 2.33.3
Fixed in:
2.33.4
Disclosed:
Jan 17, 2024

CVE-2024-22294 on NVD →

Download IP2Location Country Blocker <= 2.29.1 - Bypass via IP Spoofing

medium

The Download IP2Location Country Blocker plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.29.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and access restrictions. Attackers can supply the X-Real-IP or...

CVSS:
6.5
Affected:
up to 2.29.1
Fixed in:
2.29.2
Disclosed:
Jul 10, 2023

CVE-2023-37865 on NVD →

IP2Location Country Blocker < 2.26.9 - Authenticated Stored Cross-Site Scripting

medium

The IP2Location Country Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 2.26.9
Fixed in:
2.26.9
Disclosed:
Feb 7, 2022

IP2Location Country Blocker [ip2location-country-blocker] < 2.26.5

unknown

[en] The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from acce...

Affected:
up to 2.26.5
Fixed in:
2.26.5
Disclosed:
Feb 7, 2022

CVE-2021-25095 on NVD →

IP2Location Country Blocker [ip2location-country-blocker] < 2.26.9

unknown

The IP2Location Country Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 2.26.9
Fixed in:
2.26.9
Disclosed:
Feb 7, 2022

IP2Location Country Blocker [ip2location-country-blocker] < 2.26.6

unknown

[en] The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

Affected:
up to 2.26.6
Fixed in:
2.26.6
Disclosed:
Feb 7, 2022

CVE-2021-25108 on NVD →

IP2Location Country Blocker [ip2location-country-blocker] < 2.26.5

unknown

[en] The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

Affected:
up to 2.26.5
Fixed in:
2.26.5
Disclosed:
Feb 7, 2022

CVE-2021-25096 on NVD →

IP2Location Country Blocker <= 2.26.5 - Arbitrary Country Ban via Cross-Site Request Forgery

high

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

CVSS:
7.1
Affected:
up to 2.26.5
Fixed in:
2.26.6
Disclosed:
Jan 6, 2022

CVE-2021-25108 on NVD →

IP2Location Country Blocker <= 2.26.4 - Subscriber+ Arbitrary Country Ban

high

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing...

CVSS:
7.1
Affected:
up to 2.26.4
Fixed in:
2.26.5
Disclosed:
Jan 6, 2022

CVE-2021-25095 on NVD →

IP2Location Country Blocker <= 2.26.4 - Ban Bypass

medium

The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

CVSS:
5.3
Affected:
up to 2.26.4
Fixed in:
2.26.5
Disclosed:
Jan 6, 2022

CVE-2021-25096 on NVD →

IP2Location Country Blocker [ip2location-country-blocker] < 2.26.9

unknown

The plugin does not sanitise and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 2.26.9
Fixed in:
2.26.9

IP2Location Country Blocker [ip2location-country-blocker] < 2.38.9

unknown
Affected:
up to 2.38.9
Fixed in:
2.38.9

CVE-2025-1361 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database