Skip to content

Known CVE

IP2Location Country Blocker < 2.38.9 - Unauthenticated Information Disclosure

IP2Location Country Blocker plugin for WordPress up to version 2.38.8 contains a regular information exposure caused by missing capability checks on admin_init(), letting unauthenticated attackers view plugin settings, exploit requires no special conditions.

CVE-2025-1361

High2025CVSS 7.5CWE-862

cve2025 · wordpress · wp-plugin · wp-scan · ip2location-country-blocker · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website