CVE-2022-41650 PUBLISHED

WordPress Custom Content by Country plugin <= 3.1.2 - Broken Access Control vulnerability

Assigner: Patchstack
Reserved: 27.09.2022 Published: 17.02.2026 Updated: 17.02.2026

Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Content by Country (by Shield Security): from n/a through 3.1.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 6.5

Product Status

Vendor Paul
Product Custom Content by Country (by Shield Security)
Versions Default: unaffected
  • affected from n/a to 3.1.2 (incl.)

Credits

  • Mika | Patchstack Bug Bounty Program finder

References

Problem Types

  • CWE-862 Missing Authorization CWE