The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset/2652469 | Patch Third Party Advisory |
https://wpscan.com/vulnerability/e6dd140e-0c9d-41dc-821e-4910a13122c1 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-02-07 08:15
Updated : 2022-02-10 14:07
NVD link : CVE-2021-25096
Mitre link : CVE-2021-25096
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
ip2location
- country_blocker