WP Armour – Honeypot Anti Spam [honeypot] < 2.1.14
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dnesscarkey WP Armour – Honeypot Anti Spam allows Reflected XSS.This issue affects WP Armour – Honeypot Anti Spam: from n/a through 2.1.13.
- Affected:
- up to 2.1.14
- Fixed in:
- 2.1.14
- Disclosed:
- Mar 19, 2024
CVE-2024-29091 on NVD →
WP Armour – Honeypot Anti Spam <= 2.1.13 - Reflected Cross-Site Scripting
medium
The WP Armour – Honeypot Anti Spam plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 2.1.13
- Fixed in:
- 2.1.14
- Disclosed:
- Mar 15, 2024
CVE-2024-29091 on NVD →
WP Armour Honeypot Anti Spam <= 1.5.6 -Cross-Site Request Forgery to Arbitrary Options Update
critical
The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the wpa_save_settings() function in versions up to, and including, 1.5.6. This makes it possible for attackers to modify arbitrary site options granted they can trick an administrator into p...
- CVSS:
- 9.6
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
- Disclosed:
- Feb 8, 2021
WP Armour – Honeypot Anti Spam [honeypot] < 1.5.7
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress WP Armour – Honeypot Anti Spam plugin (versions <= 1.5.6).
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
- Disclosed:
- Feb 8, 2021
WP Armour – Honeypot Anti Spam [honeypot] < 1.5.7
unknown
The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the wpa_save_settings() function in versions up to, and including, 1.5.6. This makes it possible for attackers to modify arbitrary site options granted they can trick an administrator into p...
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
- Disclosed:
- Feb 8, 2021
WP Armour – Honeypot Anti Spam [honeypot] < 1.5.7
unknown
The plugin did not sanitise and escape its setting fields, leading to Stored Cross-Site Scripting issues. Furthermore, the lack of CSRF checks could also allow attackers to trigger the XSS via CSRF attacks against a logged in administrator
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database