IP2Location Country Blocker <= 2.26.4 - Subscriber+ Arbitrary Country Ban

2022-01-06 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 2.26.5
Affected Version<= 2.26.4
CVSS7.1High
CVECVE-2021-25095
View all IP2Location Country Blocker vulnerabilities

Vulnerability Overview

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

Technical Analysis

REMEDIATION: Update to version 2.26.5, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C