Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link, or site-wide access restrictions and access otherwise-blocked resources. | |
| Title | IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T14:30:42.342Z
Reserved: 2026-08-29T17:20:57.082Z
Link: CVE-2026-82530
Updated: 2026-09-09T14:30:34.715Z
Status : Awaiting Analysis
Published: 2026-09-09T15:17:11.967
Modified: 2026-09-09T20:16:54.383
Link: CVE-2026-82530
No data.
OpenCVE Enrichment
Updated: 2026-09-09T16:15:01Z
