IP2Location World Clock
IP2Location World Clock has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for IP2Location World Clock has a vendor fix available, so running the current release closes it.
All of these findings were reported by 0xd4rk5id3. IP2Location World Clock is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-32644IP2Location World Clock <= 1.1.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

IP2Location World Clock
Author
IP2Location
Simple widget to display analog or digital clock on your website without much hassle. IP2Location world clock gives you a range of different clock designs which is absolutely free. Supported local time, visitor’s time and custom time zone selection. Features World clock widget enable you to easily embed into your website in anywhere 46 different clock designs to choose from and the list is still growing 3 option of time selection (local time, visitor’s time and custom time zone). Support 12 hour or 24 hour time format for digital clock. Can be added via shortcode [ip2location_world_clock], please refer FAQ section for shortcode parameters.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C