8.8
CWE
352
EPSS
0.043%
Advisory Published
Updated

CVE-2024-32443: WordPress IP2Location Country Blocker plugin <= 2.34.2 - Cross Site Request Forgery (CSRF) vulnerability

First published: Mon Apr 15 2024(Updated: )

Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2.

Credit: audit@patchstack.com

Affected SoftwareAffected VersionHow to fix
IP2Location Country Blocker<=2.34.2
IP2Location Country Blocker<=2.34.2
IP2Location Country Blocker<2.34.3

Remedy

Update to 2.34.3 or a higher version.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-32443?

    CVE-2024-32443 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can allow an attacker to perform unauthorized actions on behalf of a user.

  • What versions are affected by CVE-2024-32443?

    CVE-2024-32443 affects versions of IP2Location Download IP2Location Country Blocker up to and including 2.34.2.

  • How do I fix CVE-2024-32443?

    To fix CVE-2024-32443, upgrade to a version of IP2Location Download IP2Location Country Blocker that is higher than 2.34.2.

  • Can CVE-2024-32443 impact user sessions?

    Yes, CVE-2024-32443 can impact user sessions by potentially allowing attackers to hijack sessions through forged requests.

  • Is CVE-2024-32443 specific to any platform?

    CVE-2024-32443 is specific to the IP2Location Country Blocker plugin, which is available for both IP2Location and WordPress platforms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203