Access Control Bypass in IP2Location Country Blocker Plugin for WordPress
CVE-2026-82530
6.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-82530?
The IP2Location Country Blocker plugin for WordPress, prior to version 2.45.0, is susceptible to an access control bypass vulnerability. This flaw allows unauthenticated remote attackers to manipulate the X-Real-IP HTTP header, effectively bypassing IP-based restrictions. By crafting a request that includes an allowed IP address in the X-Real-IP header, attackers can gain access to restricted pages, links, or site-wide content, undermining the security measures intended to protect such resources.
Affected Version(s)
IP2Location Country Blocker 0 < 2.45.0