cleantalk
Vulnerabilities and Security Researches

iQ Block Country, CVE-2022-1762

CVE, Research URL

CVE-2022-1762

Application

iQ Block Country

Published on
Jun 13, 2022
Research Description
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
Affected versions
max 1.1.20.
Status
vulnerable