Webence maintains the IQ Block Country product, a geolocation-based access control tool, where its vulnerability disclosures cluster around file-path handling, access control, and web-input validation issues. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webence over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41155CRITICAL Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress. | Nov 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-36873MEDIUM Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage. | Sep 23, 2021 | 5.4 | 28 | NO | YES |
CVE-2022-1762HIGH The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block fe | Jun 13, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-0246MEDIUM The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings | Apr 11, 2022 | 4.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webence.
Media articles that mention a CVE ID that affects a product developed by Webence — matched by CVE ID, not by vendor name.