PT-2026-39486 · WordPress · Ip2Location Country Blocker

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2022-50961

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IP2Location Country Blocker version 2.26.7
Description A stored cross-site scripting issue allows authenticated users to inject arbitrary JavaScript code via the Frontend Settings interface. Specifically, malicious scripts can be injected into the URL field of the Display page settings, which then execute when administrators or other authenticated users access the plugin settings page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-50961

Affected Products

Ip2Location Country Blocker