The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset/2652469 | Patch Third Party Advisory |
https://wpscan.com/vulnerability/e6dd140e-0c9d-41dc-821e-4910a13122c1 | Exploit Third Party Advisory |
https://plugins.trac.wordpress.org/changeset/2652469 | Patch Third Party Advisory |
https://wpscan.com/vulnerability/e6dd140e-0c9d-41dc-821e-4910a13122c1 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset/2652469 - Patch, Third Party Advisory | |
References | () https://wpscan.com/vulnerability/e6dd140e-0c9d-41dc-821e-4910a13122c1 - Exploit, Third Party Advisory |
Information
Published : 2022-02-07 16:15
Updated : 2024-11-21 05:54
NVD link : CVE-2021-25096
Mitre link : CVE-2021-25096
CVE.ORG link : CVE-2021-25096
JSON object : View
Products Affected
ip2location
- country_blocker
CWE
CWE-639
Authorization Bypass Through User-Controlled Key