Show filters
11 Total Results
Displaying 11-11 of 11
Sort by:
Attacker Value
Unknown
CVE-2021-25095
Disclosure Date: February 07, 2022 (last updated November 29, 2024)
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
0