Impact
IP2Location Country Blocker plugin includes a stored cross‑site scripting vulnerability that allows an attacker to store malicious script code on a site. Based on the description, it is inferred that if the plugin accepts unauthenticated input, an attacker could inject script into a field that is later rendered to all visitors. The injected code could steal user credentials, hijack sessions, or deliver further malicious payloads as the victim browser executes it.
Affected Systems
All installations of IP2Location Country Blocker with versions up to and including 2.38.3 are susceptible. Any site running one of these versions should verify its current plugin version and update if necessary.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.9, indicating a moderate risk level. The EPSS score is below 1%, suggesting a low probability of current exploitation. The issue is not listed in the CISA KEV catalog. Attackers can exploit the flaw by submitting crafted input through the plugin’s interface, which is then stored and later rendered to site visitors.
OpenCVE Enrichment
EUVD