CVE-2022-50961 MEDIUM

CVE-2022-50961: WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS

Vendor Ip2Location
Product IP2Location Country Blocker
Weakness CWE-79 · XSS
Published May 10, 2026
Last update May 24, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when administrators or other authenticated users visit the plugin settings page.

Explanation of Vulnerability in Simple Terms

02Summary

IP2Location Country Blocker contains a cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject malicious scripts. The vulnerability requires user interaction to trigger. An attacker with low-level access can craft a request that executes JavaScript in the context of another user's session, potentially compromising site functionality or stealing session data.

What an attacker can do

03Attacker Capabilities

Inject and execute JavaScript code in other users' browsers via the vulnerable component.

Potential impact on your site

04Site Impact

Authenticated users' sessions could be compromised; site functionality may be disrupted for affected users.

Conditions required to exploit

05Prerequisites

Attacker must have low-level authentication; victim must visit a malicious link or page.

Key dates

06Disclosure timeline

May 10, 2026 CVE published
May 24, 2026 Record updated

Related vulnerabilities

08Related CVE