plugin

Iq Block Country Vulnerabilities

13 known security issues reported for the Iq Block Country WordPress plugin. Most recent disclosed Aug 24, 2023.

5 medium

Running Iq Block Country on your site? Check whether your installed version is affected.

Scan your site free

iQ Block Country [iq-block-country] < 1.1.20

unknown

Update this plugin. Marcin Probola discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress iQ Block Country Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests v...

Affected:
up to 1.1.20
Fixed in:
1.1.20
Disclosed:
Aug 24, 2023

iQ Block Country [iq-block-country] < 1.2.19

unknown

[en] Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.

Affected:
up to 1.2.19
Fixed in:
1.2.19
Disclosed:
Nov 18, 2022

CVE-2022-41155 on NVD →

iQ Block Country <= 1.2.18 - Country Blocking Bypass

medium

The iQ Block Country plugin for WordPress is vulnerable to Country Blocking Bypass in versions up to, and including, 1.2.18. This is due to the improperly implemented login page verification check in the iqblockcountry_is_login_page function. This makes it possible for unauthenticated attackers to bypass the country bl...

CVSS:
5.3
Affected:
up to 1.2.18
Fixed in:
1.2.19
Disclosed:
Sep 26, 2022

CVE-2022-41155 on NVD →

iQ Block Country [iq-block-country] < 1.2.17

unknown

[en] The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

Affected:
up to 1.2.17
Fixed in:
1.2.17
Disclosed:
Jun 13, 2022

CVE-2022-1762 on NVD →

iQ Block Country <= 1.2.13 - Protection Bypass due to IP Spoofing

medium

The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

CVSS:
5.3
Affected:
up to 1.2.13
Fixed in:
1.2.17
Disclosed:
May 17, 2022

CVE-2022-1762 on NVD →

iQ Block Country [iq-block-country] < 1.2.13

unknown

[en] The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During th...

Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Apr 11, 2022

CVE-2022-0246 on NVD →

iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip

medium

The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the ext...

CVSS:
6.8
Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Mar 16, 2022

CVE-2022-0246 on NVD →

iQ Block Country [iq-block-country] < 1.2.12

unknown

[en] Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.

Affected:
up to 1.2.12
Fixed in:
1.2.12
Disclosed:
Sep 23, 2021

CVE-2021-36873 on NVD →

WordPress iQ Block Country <= 1.2.11 - Authenticated Stored Cross-Site Scripting

medium

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.

CVSS:
5.5
Affected:
up to 1.2.11
Fixed in:
1.2.12
Disclosed:
Sep 22, 2021

CVE-2021-36873 on NVD →

iQ Block Country < 1.1.20 - Reflected Cross-Site Scripting

medium

The iQ Block Country plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ipaddress’ parameter in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 1.1.20
Fixed in:
1.1.20
Disclosed:
Aug 24, 2015

iQ Block Country [iq-block-country] < 1.1.20

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Vulnerable parameter is "ipaddress". Update this plugin.

Affected:
up to 1.1.20
Fixed in:
1.1.20
Disclosed:
Aug 24, 2015

iQ Block Country [iq-block-country] < 1.1.20

unknown

The iQ Block Country plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ipaddress’ parameter in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 1.1.20
Fixed in:
1.1.20
Disclosed:
Aug 24, 2015

iQ Block Country [iq-block-country] < 1.1.20

unknown

The iQ Block Country WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability, which could be exploited via a CSRF attack against a logged in administrator.

Affected:
up to 1.1.20
Fixed in:
1.1.20

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database