Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

IP2Location — Vulnerabilities & Security Advisories 9

Browse all 9 CVE security advisories affecting IP2Location. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IP2Location provides IP geolocation and mapping services for businesses requiring location-based intelligence. Historically, the service has been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities in its web applications and APIs. The eight recorded CVEs reveal consistent weaknesses in input validation and access control mechanisms. While no major public security incidents have been documented, the pattern of vulnerabilities suggests potential risks for organizations relying on its data for security enforcement or fraud detection. Users should implement additional security layers when integrating IP2Location services into critical systems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-50961 WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS — IP2Location Country BlockerCWE-79 6.4 Medium2026-05-10
CVE-2025-39455 WordPress IP2Location Variables plugin <= 2.9.5 - CSRF to Cross Site Scripting (XSS) vulnerability — IP2Location VariablesCWE-352 7.1 High2025-04-17
CVE-2025-32644 WordPress IP2Location World Clock Plugin <= 1.1.9 - CSRF to Stored XSS vulnerability — IP2Location World ClockCWE-352 7.1 High2025-04-09
CVE-2025-1502 IP2Location Redirection <= 1.33.3 - Missing Authorization to Unauthenticated Settings Export — IP2Location RedirectionCWE-862 5.3 Medium2025-03-01
CVE-2025-1361 IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function — IP2Location Country BlockerCWE-285 7.5 High2025-02-22
CVE-2025-24731 WordPress IP2Location Country Blocker plugin <= 2.38.3 - Cross Site Scripting (XSS) vulnerability — Download IP2Location Country BlockerCWE-79 5.9 Medium2025-01-24
CVE-2023-37865 WordPress IP2Location Country Blocker plugin <= 2.29.1 - IP Bypass Vulnerability vulnerability — Download IP2Location Country BlockerCWE-290 5.3 Medium2024-06-04
CVE-2024-32443 WordPress IP2Location Country Blocker plugin <= 2.34.2 - Cross Site Request Forgery (CSRF) vulnerability — Download IP2Location Country BlockerCWE-352 4.3 Medium2024-04-15
CVE-2024-22294 WordPress Download IP2Location Country Blocker Plugin <= 2.33.3 is vulnerable to Sensitive Data Exposure — IP2Location Country BlockerCWE-200 5.3 Medium2024-01-24

This page lists every published CVE security advisory associated with IP2Location. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.