Caret Country Access Limit

Caret Country Access Limit has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Caret Country Access Limit has a vendor fix available, so running the current release closes it.

All of these findings were reported by Prasanna V Balaji. Caret Country Access Limit is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Caret Country Access Limit vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2023-45641

Caret Country Access Limit <= 1.0.2 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.0.4

Caret Country Access Limit

caret

Author

caret

0.0(0)
0/100
Last Updated
2024-03-15 (3y ago)
Active Installs
10+
Downloads
2,297
Requires WP
3.0.0+
Requires PHP
0+
Tested up to
WP 6.4.10
Created
2015-04-16 (12y ago)

APNICなどの機関で公開されているIPアドレスの一覧を自動取得し、.htaccessによるアクセス制限を国単位で行います。 紹介ページ http://www.ca-ret.co.jp/?p=1172 アクセス元の国を制限することにより、総当たり攻撃などの防止策になります。 よろしければお試しください。 Arbitrary section ■免責事項 本プラグインは無料でご利用いただけますが、ご自身の責任においてご利用ください。 利用の結果生じた損害について、一切責任を負いません。予めご了承ください。 お問い合わせ、ご意見、ご要望、不具合等は、以下お問い合わせフォームよりご連絡ください。 http://www.ca-ret.co.jp/contact ■関連事項 ISO 3166-1 wikipedia http://ja.wikipedia.org/wiki/ISO_3166-1 IPアドレスの管理について https://www.nic.ad.jp/ja/ip/admin.html このプラグインは、国別のIPアドレスの取得の際に、インターネットレジストリを使用しています。 This plugin uses the internet registery in order to validate IP addresses. Regional Internet Registry(RIR) database ftp://ftp.arin.net/pub/stats/arin/delegated-arin-extended-latest ftp://ftp.ripe.net/pub/stats/ripencc/delegated-ripencc-extended-latest ftp://ftp.apnic.net/pub/stats/apnic/delegated-apnic-extended-latest ftp://ftp.lacnic.net/pub/stats/lacnic/delegated-lacnic-extended-latest ftp://ftp.afrinic.net/pub/stats/afrinic/delegated-afrinic-extended-latest

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C