IP2Location records
8 published records for vendor ip2location.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-285 Improper Authorization1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-32443No exploit | WordPress IP2Location Country Blocker plugin <= 2.34.2 - Cross Site Request Forgery (CSRF) vulnerabilityip2location · country blocker · CWE-352 | High8.8 | — | 0.2% | Apr 15, 2024 |
30Monitor | CVE-2024-22294No exploit | WordPress Download IP2Location Country Blocker Plugin <= 2.33.3 is vulnerable to Sensitive Data Exposureip2location · country blocker · CWE-200 | High7.5 | — | 0.5% | Jan 24, 2024 |
28Monitor | CVE-2021-25095No exploit | IP2Location Country Blocker < 2.26.5 - Subscriber+ Arbitrary Country Banip2location · country blocker · CWE-352 | High7.1 | — | 0.5% | Feb 7, 2022 |
28Monitor | CVE-2021-25108No exploit | IP2Location Country Blocker < 2.26.6 - Arbitrary Country Ban via CSRFip2location · country blocker · CWE-352 | High7.1 | — | 0.5% | Feb 7, 2022 |
26Monitor | CVE-2021-25096No exploit | IP2Location Country Blocker < 2.26.5 - Ban Bypassip2location · country blocker · CWE-639 | Medium6.5 | — | 1.0% | Feb 7, 2022 |
21Monitor | CVE-2025-1361Proof of concept | IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Functionip2location · country blocker · CWE-285 | Medium5.3 | — | 1.3% | Feb 22, 2025 |
21Monitor | CVE-2023-37865No exploit | WordPress IP2Location Country Blocker plugin <= 2.29.1 - IP Bypass Vulnerability vulnerabilityip2location · country blocker · CWE-290 | Medium5.3 | — | 0.4% | Jun 4, 2024 |
19Monitor | CVE-2025-24731No exploit | WordPress IP2Location Country Blocker plugin <= 2.38.3 - Cross Site Scripting (XSS) vulnerabilityip2location · country blocker · CWE-79 | Medium4.8 | — | 0.3% | Jan 24, 2025 |
- CVE-2024-3244335Monitor
WordPress IP2Location Country Blocker plugin <= 2.34.2 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%ip2location · country blockerApr 15, 2024
- CVE-2024-2229430Monitor
WordPress Download IP2Location Country Blocker Plugin <= 2.33.3 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5No exploitEPSS 0%ip2location · country blockerJan 24, 2024
- CVE-2021-2509528Monitor
IP2Location Country Blocker < 2.26.5 - Subscriber+ Arbitrary Country Ban
HighCVSS 7.1No exploitEPSS 1%ip2location · country blockerFeb 7, 2022
- CVE-2021-2510828Monitor
IP2Location Country Blocker < 2.26.6 - Arbitrary Country Ban via CSRF
HighCVSS 7.1No exploitEPSS 0%ip2location · country blockerFeb 7, 2022
- CVE-2021-2509626Monitor
IP2Location Country Blocker < 2.26.5 - Ban Bypass
MediumCVSS 6.5No exploitEPSS 1%ip2location · country blockerFeb 7, 2022
- CVE-2025-136121Monitor
IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function
MediumCVSS 5.3Proof of conceptEPSS 1%ip2location · country blockerFeb 22, 2025
- CVE-2023-3786521Monitor
WordPress IP2Location Country Blocker plugin <= 2.29.1 - IP Bypass Vulnerability vulnerability
MediumCVSS 5.3No exploitEPSS 0%ip2location · country blockerJun 4, 2024
- CVE-2025-2473119Monitor
WordPress IP2Location Country Blocker plugin <= 2.38.3 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%ip2location · country blockerJan 24, 2025