Description
IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link, or site-wide access restrictions and access otherwise-blocked resources.
Published: 2026-09-09
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IP2Location Country Blocker WordPress plugin versions before 2.45.0 contain an access control bypass flaw that lets attackers alter the X‑Real‑IP HTTP header to impersonate an allowed IP. By forging this header they can circumvent page, link, or site-wide IP restrictions and reach normally protected content without authentication.

Affected Systems

WordPress sites running the IP2Location Country Blocker plugin earlier than version 2.45.0 are affected. No specific vendor versions beyond the plugin listing are mentioned, so any WordPress installation using that plugin at a pre‑2.45.0 release is at risk.

Risk and Exploitability

The vulnerability is assigned a CVSS score of 6.9, indicating moderate severity. No EPSS data is available and the flaw is not in the CISA KEV catalog. Attackers need only to send a crafted HTTP request with a custom X‑Real‑IP header; authentication is not required and no server‑side state is needed. The low barrier to exploitation suggests that remote attackers could easily abuse the flaw if the plugin remains unpatched.

Generated by OpenCVE AI on September 9, 2026 at 16:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade IP2Location Country Blocker to version 2.45.0 or later.
  • Reconfigure the web server or reverse proxy to strip or ignore the X-Real-IP header, ensuring it is only set by trusted internal proxies.
  • Limit the IP blocker's scope or disable it until the plugin is updated, and monitor traffic for suspicious X-Real-IP usage.

Generated by OpenCVE AI on September 9, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link, or site-wide access restrictions and access otherwise-blocked resources.
Title IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:30:42.342Z

Reserved: 2026-08-29T17:20:57.082Z

Link: CVE-2026-82530

cve-icon Vulnrichment

Updated: 2026-09-09T14:30:34.715Z

cve-icon NVD

Status : Received

Published: 2026-09-09T15:17:11.967

Modified: 2026-09-09T15:17:11.967

Link: CVE-2026-82530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:15:01Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing