PT-2022-14094 · WordPress · Iq Block Country

Daniel Ruf

·

Published

2022-06-13

·

Updated

2023-04-04

·

CVE-2022-1762

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions iQ Block Country WordPress plugin versions prior to 1.2.20
Description The issue allows threat actors to bypass the block feature by spoofing HTTP headers, as the plugin does not properly check these headers to validate the origin IP address.
Recommendations For versions prior to 1.2.20, update to version 1.2.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality until the update is applied.

Exploit

Fix

Related Identifiers

CVE-2022-1762

Affected Products

Iq Block Country