plugin

Honeypot Vulnerabilities

6 known security issues reported for the Honeypot WordPress plugin. Most recent disclosed Mar 19, 2024.

1 critical 1 medium

Running Honeypot on your site? Check whether your installed version is affected.

Scan your site free

WP Armour &#8211; Honeypot Anti Spam [honeypot] < 2.1.14

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dnesscarkey WP Armour – Honeypot Anti Spam allows Reflected XSS.This issue affects WP Armour – Honeypot Anti Spam: from n/a through 2.1.13.

Affected:
up to 2.1.14
Fixed in:
2.1.14
Disclosed:
Mar 19, 2024

CVE-2024-29091 on NVD →

WP Armour – Honeypot Anti Spam <= 2.1.13 - Reflected Cross-Site Scripting

medium

The WP Armour – Honeypot Anti Spam plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 2.1.13
Fixed in:
2.1.14
Disclosed:
Mar 15, 2024

CVE-2024-29091 on NVD →

WP Armour Honeypot Anti Spam <= 1.5.6 -Cross-Site Request Forgery to Arbitrary Options Update

critical

The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the wpa_save_settings() function in versions up to, and including, 1.5.6. This makes it possible for attackers to modify arbitrary site options granted they can trick an administrator into p...

CVSS:
9.6
Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Feb 8, 2021

WP Armour &#8211; Honeypot Anti Spam [honeypot] < 1.5.7

unknown

Cross-Site Scripting (XSS) vulnerability found in WordPress WP Armour – Honeypot Anti Spam plugin (versions <= 1.5.6).

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Feb 8, 2021

WP Armour &#8211; Honeypot Anti Spam [honeypot] < 1.5.7

unknown

The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the wpa_save_settings() function in versions up to, and including, 1.5.6. This makes it possible for attackers to modify arbitrary site options granted they can trick an administrator into p...

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Feb 8, 2021

WP Armour &#8211; Honeypot Anti Spam [honeypot] < 1.5.7

unknown

The plugin did not sanitise and escape its setting fields, leading to Stored Cross-Site Scripting issues. Furthermore, the lack of CSRF checks could also allow attackers to trigger the XSS via CSRF attacks against a logged in administrator

Affected:
up to 1.5.7
Fixed in:
1.5.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database