CyberRota Analysis
AI-GeneratedThe IP2Location Country Blocker plugin for WordPress versions prior to 2.45.0 is vulnerable to an access control bypass, enabling unauthenticated remote attackers to manipulate the X-Real-IP HTTP header. This exploitation allows attackers to circumvent IP-based restrictions, granting them access to restricted resources. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential unauthorized access risks.
Original NVD Description
IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link, or site-wide access restrictions and access otherwise-blocked resources.