IP2Location is a geolocation intelligence vendor whose vulnerability profile centers on its Country Blocker product, a web-application filtering tool deployed to restrict access based on geographic origin. The recurring weaknesses—CSRF, missing authorization, authentication bypass through spoofing, user-controlled authorization keys, and exposure of sensitive information—reflect common gaps in the authentication and session-management layers of administrative interfaces, and public exploit code has acquired availability for vulnerabilities in this product line. Defenders should prioritize access controls and network isolation around Country Blocker deployments; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ip2location over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1361MEDIUM The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on | Feb 22, 2025 | 5.3 | 28 | NO | YES |
CVE-2021-25095HIGH The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any a | Feb 7, 2022 | 7.1 | 24 | NO | NO |
CVE-2024-32443HIGH Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2 | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2021-25108HIGH The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logg | Feb 7, 2022 | 7.1 | 23 | NO | NO |
CVE-2021-25096MEDIUM The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL | Feb 7, 2022 | 6.5 | 22 | NO | NO |
CVE-2024-22294HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through | Jan 24, 2024 | 7.5 | 19 | NO | NO |
CVE-2025-24731MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker ip2location-country-blocker a | Jan 24, 2025 | 4.8 | 16 | NO | NO |
CVE-2023-37865MEDIUM Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affec | Jun 4, 2024 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ip2location.
Media articles that mention a CVE ID that affects a product developed by Ip2location — matched by CVE ID, not by vendor name.