IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function
2025-02-21 19:56
abrahackStrategic Overview
StatusPatched in 2.38.9
Affected PluginIP2Location Country Blocker
Affected Version
<= 2.38.8CVSS7.5High
CVE
CVE-2025-1361Vulnerability Overview
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.
Technical Analysis
REMEDIATION: Update to version 2.38.9, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C