📦 Country Blocker

by Ip2location

🔍 What is Country Blocker?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-1361

HIGH CVSS 7.5 Feb 22, 2025

The IP2Location Country Blocker WordPress plugin exposes sensitive configuration settings to unauthenticated users due to missing capability checks. This allows attackers to view plugin settings witho...

CVE-2021-25108

HIGH CVSS 7.1 Feb 7, 2022

This vulnerability in the IP2Location Country Blocker WordPress plugin allows attackers to trick logged-in administrators into blocking arbitrary countries or all countries at once via CSRF attacks. T...

CVE-2021-25095

HIGH CVSS 7.1 Feb 7, 2022

The IP2Location Country Blocker WordPress plugin before version 2.26.5 lacks proper authorization and CSRF protection in its AJAX endpoint, allowing any authenticated user (even with subscriber privil...

CVE-2025-24731

MEDIUM CVSS 5.9 Jan 24, 2025

This stored cross-site scripting (XSS) vulnerability in the IP2Location Country Blocker WordPress plugin allows attackers to inject malicious scripts into web pages. When exploited, these scripts exec...

CVE-2023-37865

MEDIUM CVSS 5.3 Jun 4, 2024

This vulnerability allows attackers to bypass IP-based country blocking restrictions in the IP2Location Country Blocker WordPress plugin by spoofing IP addresses. It affects all WordPress sites using ...