SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82530

MEDIUM · CVSS 5.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The IP2Location Country Blocker plugin for WordPress versions prior to 2.45.0 is vulnerable to an access control bypass, enabling unauthenticated remote attackers to manipulate the X-Real-IP HTTP header. This exploitation allows attackers to circumvent IP-based restrictions, granting them access to restricted resources. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential unauthorized access risks.

CVE
CVE-2026-82530
Severity
MEDIUM
CVSS
5.3
EPSS
0.27%
WordPress

Original NVD Description

IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link, or site-wide access restrictions and access otherwise-blocked resources.