IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link, or site-wide access restrictions and access otherwise-blocked resources.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 15:17
Updated : 2026-09-09 20:16
NVD link : CVE-2026-82530
Mitre link : CVE-2026-82530
CVE.ORG link : CVE-2026-82530
JSON object : View
Products Affected
No product.
CWE
CWE-290
Authentication Bypass by Spoofing
