WordPress 的 IP2Location Country Blocker 插件在 2.45.0 版本之前存在访问控制绕过漏洞,允许未认证的远程攻击者通过伪造 HTTP 请求头来绕过基于 IP 的限制。攻击者可以将 请求头设置为允许列表中的 IP 地址,从而绕过针对特定页面、链接或整个站点的访问限制,进而访问原本被阻止的资源。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IP2Location | IP2Location Country Blocker | < 2.45.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IP2Location | IP2Location Country Blocker | 0 ~ 2.45.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet