VulnerabilityModified
CVE-2022-1762
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
HIGH 7.5EPSS 1.24%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- webence/iq block country
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/03254977-37cc-4365-979b-326f9637be85Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/03254977-37cc-4365-979b-326f9637be85Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.