IP2Location Country Blocker plugin for WordPress up to version 2.38.8 contains a regular information exposure caused by missing capability checks on admin_init(), letting unauthenticated attackers view plugin settings, exploit requires no special conditions.
id: CVE-2025-1361
info:
name: IP2Location Country Blocker < 2.38.9 - Unauthenticated Information
...