CVE-2021-25108

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
07/02/2022
Last modified:
25/02/2022

Description

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ip2location:country_blocker:*:*:*:*:*:wordpress:*:* 2.26.6 (excluding)