What the vulnerability does
01Description
WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when administrators or other authenticated users visit the plugin settings page.
Explanation of Vulnerability in Simple Terms
02Summary
IP2Location Country Blocker contains a cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject malicious scripts. The vulnerability requires user interaction to trigger. An attacker with low-level access can craft a request that executes JavaScript in the context of another user's session, potentially compromising site functionality or stealing session data.
What an attacker can do
03Attacker Capabilities
Inject and execute JavaScript code in other users' browsers via the vulnerable component.
Potential impact on your site
04Site Impact
Authenticated users' sessions could be compromised; site functionality may be disrupted for affected users.
Conditions required to exploit
05Prerequisites
Attacker must have low-level authentication; victim must visit a malicious link or page.
Key dates
06Disclosure timeline
May 10, 2026
CVE published
May 24, 2026
Record updated