Impact
The IP2Location Country Blocker WordPress plugin versions before 2.45.0 contain an access control bypass flaw that lets attackers alter the X‑Real‑IP HTTP header to impersonate an allowed IP. By forging this header they can circumvent page, link, or site-wide IP restrictions and reach normally protected content without authentication.
Affected Systems
WordPress sites running the IP2Location Country Blocker plugin earlier than version 2.45.0 are affected. No specific vendor versions beyond the plugin listing are mentioned, so any WordPress installation using that plugin at a pre‑2.45.0 release is at risk.
Risk and Exploitability
The vulnerability is assigned a CVSS score of 6.9, indicating moderate severity. No EPSS data is available and the flaw is not in the CISA KEV catalog. Attackers need only to send a crafted HTTP request with a custom X‑Real‑IP header; authentication is not required and no server‑side state is needed. The low barrier to exploitation suggests that remote attackers could easily abuse the flaw if the plugin remains unpatched.
OpenCVE Enrichment