Extension WordPress
Vulnérabilités iQ Block Country
Cette page rassemble les failles publiées pour iQ Block Country, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de iQ Block Country
5 fiches
iQ Block Country <= 1.2.18 – Country Blocking Bypass
The iQ Block Country plugin for WordPress is vulnerable to Country Blocking Bypass in versions up to, and including, 1.2.18. This is due to the improperly implemented login page verification check in the iqblockcountry_is_login_page function. This makes it…
*-1.2.18
1.2.19
26/09/2022
iQ Block Country <= 1.2.13 – Protection Bypass due to IP Spoofing
The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
*-1.2.13
1.2.17
17/05/2022
iQ Block Country < 1.2.13 – Admin+ Arbitrary File Deletion via Zip Slip
The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading…
[*, 1.2.13)
1.2.13
16/03/2022
WordPress iQ Block Country <= 1.2.11 – Authenticated Stored Cross-Site Scripting
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions
*-1.2.11
1.2.12
23/09/2021
iQ Block Country < 1.1.20 – Reflected Cross-Site Scripting
The iQ Block Country plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ipaddress’ parameter in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 1.1.20)
1.1.20
24/08/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.