Description
The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP address without proper validation or considering if the server is behind a trusted proxy. This makes it possible for unauthenticated attackers to bypass IP-based access restrictions by spoofing their IP address via the X-Forwarded-For header.
Problem types
CWE-348 Use of Less Trusted Source
Product status
* (semver)
Timeline
| 2026-01-06: | Disclosed |
Credits
Ivan Cese
References
www.wordfence.com/...-dc2e-4e9f-9318-65dfee1c80e9?source=cve
plugins.trac.wordpress.org/...untry/trunk/aablockcountry.php
plugins.trac.wordpress.org/.../tags/1.0.1/aablockcountry.php