Executive brief
IniLerm Advanced IP Blocker, a tool used to manage and restrict access to websites based on IP addresses, contains a security flaw that allows for malicious script injection. An attacker could use this vulnerability to execute unauthorized code in a user's browser when they visit a compromised page. This could lead to the theft of session cookies, unauthorized access to user accounts, or the defacement of the website's interface.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the IniLerm Advanced IP Blocker plugin (versions up to and including 8.10.7). The flaw stems from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts that are executed within the victim's browser context. This is a client-side vulnerability where the attack payload is executed by modifying the Document Object Model (DOM) environment. Successful exploitation typically requires a victim to click a specially crafted link or visit a malicious URL. This can result in the disclosure of sensitive information, such as session tokens, or the performance of unauthorized actions on behalf of the user.
Affected products
- IniLerm Advanced IP Blocker n/a through 8.10.7
Timeline
- 2026-05-27: advisory: Initial disclosure of CVE-2026-42739