Input validation vulnerability in IP2Location Country Blocker 2.26.9

The IP2Location Country Blocker plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. This plugin is used to control which countries can access a WordPress website. The vulnerability exists in versions up to, and including, 2.26.8 of the plugin. This issue occurs because the plugin does not properly check the data it receives or escape data it sends. This makes it possible for an attacker, who is already logged into the website, to inject malicious code or scripts into webpages. This malicious code will then execute whenever a user visits the injected page.

Detected in:

IP2Location Country Blocker fixed vulnerable versions: >= * < 2.26.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.