nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-50961 CVE-2022-50961
MEDIUM
WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS
Record summary
CVE-2022-50961 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when administrators or other authenticated users visit the plugin settings page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
IP2Location Country BlockerBrowse IP2Location / IP2Location Country Blocker | CVE List | 2.26.7 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin IP2Location Country Blocker 2.26.7 - Stored Cross Site Scripting (XSS) (Authenticated)ExploitDB exploitby Ahmet Serkan AriNot analyzed1 file
References
4Product Referenceproduct
https://wordpress.org/plugins/ip2location-country-blocker ExploitDB-50709exploit
https://www.exploit-db.com/exploits/50709 VulnCheck Advisory: WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSSThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-ip2location-country-blocker-stored-xss