5.9
CVSSv3

CVE-2025-24731

CVSSv4: NA | CVSSv3: 5.9 | CVSSv2: NA | VMScore: 690 | EPSS: 0.00033 | KEV: Not Included
Published: 24/01/2025 Updated: 24/01/2025

Vulnerability Summary

Stored Cross-Site Scripting in IP2Location Country Blocker Versions Pre-2.38.3

IP2Location Download IP2Location Country Blocker has a Stored Cross-site Scripting (XSS) vulnerability. This issue affects versions from unknown up to 2.38.3.

Solution

Update the WordPress Download IP2Location Country Blocker wordpress plugin to the latest available version (at least 2.38.4).
Vulnerable Product Search on Vulmon Subscribe to Product

ip2location download ip2location country blocker