CVE-2022-1762

The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:webence:iq_block_country:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 03:42

Type Values Removed Values Added
CWE CWE-290

04 Apr 2023, 15:15

Type Values Removed Values Added
CWE CWE-639 CWE-290
Summary The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers. The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

21 Jun 2022, 18:26

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/03254977-37cc-4365-979b-326f9637be85 - (MISC) https://wpscan.com/vulnerability/03254977-37cc-4365-979b-326f9637be85 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
First Time Webence
Webence iq Block Country
CPE cpe:2.3:a:webence:iq_block_country:*:*:*:*:*:wordpress:*:*

13 Jun 2022, 13:26

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-13 13:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-1762

Mitre link : CVE-2022-1762

CVE.ORG link : CVE-2022-1762


JSON object : View

Products Affected

webence

  • iq_block_country
CWE

No CWE.