First published: Mon Feb 07 2022(Updated: )
The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
IP2Location Country Blocker | <2.26.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25108 is considered a high severity vulnerability due to its potential impact on site accessibility and security.
To fix CVE-2021-25108, update the IP2Location Country Blocker plugin to version 2.26.6 or later.
CVE-2021-25108 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the IP2Location Country Blocker plugin.
Users of the IP2Location Country Blocker WordPress plugin prior to version 2.26.6 are affected by CVE-2021-25108.
Attackers exploiting CVE-2021-25108 can block specific or all countries for logged-in users, disrupting site access.