{ "schema_version": "1.4.0", "id": "GHSA-r5r8-g427-8mp7", "modified": "2022-02-11T00:01:05Z", "published": "2022-02-08T00:00:27Z", "aliases": [ "CVE-2021-25108" ], "details": "The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25108" }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/2653459" }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/9d416ca3-bd02-4fcf-b3b8-f2f2280d02d2" } ], "database_specific": { "cwe_ids": [ "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-02-07T16:15:00Z" } }