← back
CVE-2022-1762

iQ Block Country < 1.2.20 - Protection Bypass due to IP Spoofing

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.