Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ip2location

First CVE: Feb 7, 2022Active for: 4 yearsTotal CVEs: 8

IP2Location is a geolocation intelligence vendor whose vulnerability profile centers on its Country Blocker product, a web-application filtering tool deployed to restrict access based on geographic origin. The recurring weaknesses—CSRF, missing authorization, authentication bypass through spoofing, user-controlled authorization keys, and exposure of sensitive information—reflect common gaps in the authentication and session-management layers of administrative interfaces, and public exploit code has acquired availability for vulnerabilities in this product line. Defenders should prioritize access controls and network isolation around Country Blocker deployments; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ip2location over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2022
4 years ago
Most Recent CVE
Feb 22, 2025
517 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-1361MEDIUM
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on
Feb 22, 20255.328NOYES
CVE-2021-25095HIGH
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any a
Feb 7, 20227.124NONO
CVE-2024-32443HIGH
Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2
Apr 15, 20248.823NONO
CVE-2021-25108HIGH
The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logg
Feb 7, 20227.123NONO
CVE-2021-25096MEDIUM
The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL
Feb 7, 20226.522NONO
CVE-2024-22294HIGH
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through
Jan 24, 20247.519NONO
CVE-2025-24731MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker ip2location-country-blocker a
Jan 24, 20254.816NONO
CVE-2023-37865MEDIUM
Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec
Jun 4, 20245.315NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low1 (12.5%)
High1 (12.5%)
None6 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ip2location.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ip2location — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ip2location's Products

View all 3 CNAs →

Top CWEs