Maspik – Spam blacklist <= 2.9.1 - Unauthenticated Stored Cross-Site Scripting
high
The Maspik – Spam blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use...
- CVSS:
- 7.2
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Aug 12, 2026
CVE-2026-28003 on NVD →
Maspik <= 2.5.6 - Authenticated (Subscriber+) Missing Authorization to Spam Log Export
medium
The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log databas...
- CVSS:
- 4.3
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.7
- Disclosed:
- Sep 9, 2025
CVE-2025-9979 on NVD →
Maspik <= 2.5.6 - Cross-Site Request Forgery
medium
The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.7
- Disclosed:
- Sep 9, 2025
CVE-2025-9888 on NVD →
Maspik – Ultimate Spam Protection [contact-forms-anti-spam] < 2.2.8
unknown
[en] Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7.
- Affected:
- up to 2.2.8
- Fixed in:
- 2.2.8
- Disclosed:
- Dec 6, 2024
CVE-2024-53806 on NVD →
Maspik – Spam blacklist <= 2.2.7 - Cross-Site Request Forgery to Plugin Settings Change
medium
The Maspik – Advanced Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.7. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to change plugin settings via a forged re...
- CVSS:
- 4.3
- Affected:
- up to 2.2.7
- Fixed in:
- 2.2.8
- Disclosed:
- Dec 2, 2024
CVE-2024-53806 on NVD →
Maspik – Spam blacklist <= 2.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Oct 2, 2024
CVE-2024-9182 on NVD →
Maspik – Ultimate Spam Protection [contact-forms-anti-spam] < 0.10.4
unknown
[en] Authentication Bypass by Spoofing vulnerability in yonifre Maspik – Spam blacklist allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maspik – Spam blacklist: from n/a through 0.10.3.
- Affected:
- up to 0.10.4
- Fixed in:
- 0.10.4
- Disclosed:
- Jun 4, 2024
CVE-2023-48271 on NVD →
Maspik – Ultimate Spam Protection [contact-forms-anti-spam] < 0.10.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Maspik – Spam Blacklist allows Stored XSS.This issue affects Maspik – Spam Blacklist: from n/a through 0.10.6.
- Affected:
- up to 0.10.7
- Fixed in:
- 0.10.7
- Disclosed:
- Mar 13, 2024
CVE-2024-25101 on NVD →
Maspik – Spam blacklist <= 0.10.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 0.10.6
- Fixed in:
- 0.10.7
- Disclosed:
- Feb 12, 2024
CVE-2024-25101 on NVD →
Maspik – Ultimate Spam Protection [contact-forms-anti-spam] < 0.9.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Maspik – Spam Blacklist allows Stored XSS.This issue affects Maspik – Spam Blacklist: from n/a through 0.9.2.
- Affected:
- up to 0.9.3
- Fixed in:
- 0.9.3
- Disclosed:
- Nov 30, 2023
CVE-2023-48272 on NVD →
Maspik – Spam blacklist <= 0.9.2 - Unauthenticated Stored Cross-Site Scripting via efas_add_to_log
medium
The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the efas_add_to_log function in all versions up to, and including, 0.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 6.1
- Affected:
- up to 0.9.2
- Fixed in:
- 0.9.3
- Disclosed:
- Nov 21, 2023
CVE-2023-48272 on NVD →
Maspik – Spam blacklist <= 0.10.3 - Bypass
medium
The Maspik – Spam Blacklist plugin for WordPress is vulnerable to IP Filtering Bypass in all versions up to, and including, 0.10.3 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to bypass IP-based restrictions.
- CVSS:
- 5.3
- Affected:
- up to 0.10.3
- Fixed in:
- 0.10.4
- Disclosed:
- Nov 21, 2023
CVE-2023-48271 on NVD →
Maspik – Ultimate Spam Protection [contact-forms-anti-spam] < 0.7.9
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in yonifre Maspik – Spam Blacklist plugin <= 0.7.8 versions.
- Affected:
- up to 0.7.9
- Fixed in:
- 0.7.9
- Disclosed:
- May 26, 2023
CVE-2023-24008 on NVD →
Maspik – Spam blacklist <= 0.7.8 - Cross-Site Request Forgery
medium
The Maspik plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.7.8. This is due to missing or incorrect nonce validation in the file /admin/partials/contact-forms-anti-spam-log.php. This makes it possible for unauthenticated attackers to clear plugin logs and stat count...
- CVSS:
- 4.3
- Affected:
- up to 0.7.8
- Fixed in:
- 0.7.9
- Disclosed:
- Feb 27, 2023
CVE-2023-24008 on NVD →
Maspik – Ultimate Spam Protection [contact-forms-anti-spam] < 2.1.3
unknown
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
CVE-2024-9182 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database