IP2Location Country Blocker

IP2Location Country Blocker has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 9 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 3 high. 2022 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (22%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key.

Every one of the 9 issues recorded for IP2Location Country Blocker has a vendor fix available, so running the current release closes all known holes.

6 independent researchers contributed these findings, most of them (2) reported by Kévin Mosbahi (Mika). IP2Location Country Blocker is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

9

Get automatic notifications for all IP2Location Country Blocker vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2025-1361

IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function

Read the full analysis

Vulnerability Records

9 records
2025-02-21 19:56CVE-2025-1361
7.5
High
abrahackYes
2025-01-24 00:00CVE-2025-24731
4.4
Medium
Malvin Valerian GultomYes
2024-04-12 00:00CVE-2024-32443
4.3
Medium
Majed RefaeaYes
2024-01-17 00:00CVE-2024-22294
5.3
Medium
Kévin Mosbahi (Mika)Yes
2023-07-10 00:00CVE-2023-37865
6.5
Medium
Kévin Mosbahi (Mika)Yes
2022-02-07 00:00N/A
6.4
Medium
Ahmet Serkan AriYes
2022-01-06 00:00CVE-2021-25096
5.3
Medium
AnonymousYes
2022-01-06 00:00CVE-2021-25095
7.1
High
Krzysztof ZającYes
2022-01-06 00:00CVE-2021-25108
7.1
High
Krzysztof ZającYes
Showing 1–9 of 9 reports
IP2Location Country Blocker banner
Latestv2.45.0

IP2Location Country Blocker

IP2Location

Author

IP2Location

4.2(127)
84/100
Last Updated
2026-09-02 (11d ago)
Active Installs
30,000+
Downloads
1,820,981
Requires WP
4.6+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2013-11-26 (13y ago)

This plugin will NOT work if any cache plugin is enabled. This plugin enables user to block unwanted traffic from accessing your frontend (blog pages) or backend (admin area) by countries or proxy servers. It helps to reduce spam and unwanted sign ups easily by preventing unwanted visitors from browsing a particular page or entire website. Key Features Allow you to block the access from multiple countries. Allow you to block the access by country grouping, such as EU, APAC, and so on. Allow you to block the access from anonymous proxies. Allow you to block the access by IP ranges. Allow you to whitelist the crawler, for example, Google, Bing, Yandex, and so on, to index your pages (SEO friendly). Supports IPv4 and IPv6 Default to 403 error (Permission Denied) display Allow you to customize your own 403 page. Send you an email notification if some one is trying to access your admin area. Provide you statistical report of traffics blocked. This plugin supports both IP2Location BIN data and web service for IP geolocation lookup. If you would like to use the IP2Location geolocation BIN data, you can easily download and update the BIN data via the plugin settings page. Alternatively, you can also download and update the BIN data file manually using the below links: IP Geolocation file download: IP2Location & IP2Proxy LITE database (Free) IP2Location & IP2Proxy Commercial database (Comprehensive) To use the IP2Location IP geolocation web service (REST API) for geolocation, you’ll need to register an account at IP2Location.io IP Geolocation API. A free plan is available. More Information Please visit us at https://www.ip2location.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C