CVE-2023-2488
- EPSS 0.35%
- Veröffentlicht 05.06.2023 14:15:10
- Zuletzt bearbeitet 08.01.2025 17:15:11
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could ...
CVE-2023-2489
- EPSS 0.09%
- Veröffentlicht 05.06.2023 14:15:10
- Zuletzt bearbeitet 08.01.2025 17:15:11
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even wh...
CVE-2022-4120
- EPSS 22.47%
- Veröffentlicht 26.12.2022 13:15:12
- Zuletzt bearbeitet 14.04.2025 14:15:21
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a ...
CVE-2021-24517
- EPSS 0.16%
- Veröffentlicht 06.09.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:13
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_htm...
CVE-2021-24245
- EPSS 17.94%
- Veröffentlicht 06.05.2021 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:52:40
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected C...