CVE-2021-25095
07.02.2022, 16:15
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
| Vendor | Product | Version |
|---|---|---|
| ip2location | country_blocker | 𝑥 < 2.26.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration