Authorization Bypass in Advanced Country Blocker Plugin for WordPress
CVE-2026-1675
5.3MEDIUM
What is CVE-2026-1675?
The Advanced Country Blocker plugin for WordPress suffers from an Authorization Bypass vulnerability due to a predictable default value for the secret bypass key established during installation. This oversight permits unauthenticated attackers to circumvent the geolocation blocking feature by merely appending the static bypass key to URLs. If site administrators fail to change this default key, it poses a significant risk, as attackers can gain unauthorized access to content restricted by geolocation rules.
Affected Version(s)
Advanced Country Blocker 0 <= 2.3.1