Input validation vulnerability in IP2Location Country Blocker 2.29.1

The Download IP2Location Country Blocker plugin for WordPress is vulnerable to a security issue called IP Address Spoofing in versions up to and including 2.29.1. This means that there is not enough control over where the IP Address information comes from when logging requests and restricting access to certain pages. Attackers can use the X-Real-IP or X-Forwarded-For header to pass a different IP Address which will be logged, allowing them to access pages that would otherwise be blocked.

Detected in:

IP2Location Country Blocker fixed vulnerable versions: >= * <= 2.29.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.