Known CVE
IP2Location Country Blocker < 2.38.9 - Unauthenticated Information Disclosure
IP2Location Country Blocker plugin for WordPress up to version 2.38.8 contains a regular information exposure caused by missing capability checks on admin_init(), letting unauthenticated attackers view plugin settings, exploit requires no special conditions.
CVE-2025-1361
High2025CVSS 7.5CWE-862
cve2025 · wordpress · wp-plugin · wp-scan · ip2location-country-blocker · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website