iQ Block Country [iq-block-country] < 1.1.20
unknown
Update this plugin.
Marcin Probola discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress iQ Block Country Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests v...
- Affected:
- up to 1.1.20
- Fixed in:
- 1.1.20
- Disclosed:
- Aug 24, 2023
iQ Block Country [iq-block-country] < 1.2.19
unknown
[en] Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
- Affected:
- up to 1.2.19
- Fixed in:
- 1.2.19
- Disclosed:
- Nov 18, 2022
CVE-2022-41155 on NVD →
iQ Block Country <= 1.2.18 - Country Blocking Bypass
medium
The iQ Block Country plugin for WordPress is vulnerable to Country Blocking Bypass in versions up to, and including, 1.2.18. This is due to the improperly implemented login page verification check in the iqblockcountry_is_login_page function. This makes it possible for unauthenticated attackers to bypass the country bl...
- CVSS:
- 5.3
- Affected:
- up to 1.2.18
- Fixed in:
- 1.2.19
- Disclosed:
- Sep 26, 2022
CVE-2022-41155 on NVD →
iQ Block Country [iq-block-country] < 1.2.17
unknown
[en] The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
- Affected:
- up to 1.2.17
- Fixed in:
- 1.2.17
- Disclosed:
- Jun 13, 2022
CVE-2022-1762 on NVD →
iQ Block Country <= 1.2.13 - Protection Bypass due to IP Spoofing
medium
The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
- CVSS:
- 5.3
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.17
- Disclosed:
- May 17, 2022
CVE-2022-1762 on NVD →
iQ Block Country [iq-block-country] < 1.2.13
unknown
[en] The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During th...
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Apr 11, 2022
CVE-2022-0246 on NVD →
iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip
medium
The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the ext...
- CVSS:
- 6.8
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Mar 16, 2022
CVE-2022-0246 on NVD →
iQ Block Country [iq-block-country] < 1.2.12
unknown
[en] Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.
- Affected:
- up to 1.2.12
- Fixed in:
- 1.2.12
- Disclosed:
- Sep 23, 2021
CVE-2021-36873 on NVD →
WordPress iQ Block Country <= 1.2.11 - Authenticated Stored Cross-Site Scripting
medium
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.
- CVSS:
- 5.5
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.12
- Disclosed:
- Sep 22, 2021
CVE-2021-36873 on NVD →
iQ Block Country < 1.1.20 - Reflected Cross-Site Scripting
medium
The iQ Block Country plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ipaddress’ parameter in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 1.1.20
- Fixed in:
- 1.1.20
- Disclosed:
- Aug 24, 2015
iQ Block Country [iq-block-country] < 1.1.20
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Vulnerable parameter is "ipaddress".
Update this plugin.
- Affected:
- up to 1.1.20
- Fixed in:
- 1.1.20
- Disclosed:
- Aug 24, 2015
iQ Block Country [iq-block-country] < 1.1.20
unknown
The iQ Block Country plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ipaddress’ parameter in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 1.1.20
- Fixed in:
- 1.1.20
- Disclosed:
- Aug 24, 2015
iQ Block Country [iq-block-country] < 1.1.20
unknown
The iQ Block Country WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability, which could be exploited via a CSRF attack against a logged in administrator.
- Affected:
- up to 1.1.20
- Fixed in:
- 1.1.20
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database