Spam Free WordPress <= 1.9.3 - Full Path Disclosure
high
The Spam Free WordPress plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 1.9.3 via various files. This makes it possible for unauthenticated attackers to extract sensitive data which consists of full application path details that can be used to exploit additional vulnerabilit...
- CVSS:
- 7.5
- Affected:
- up to 1.9.3
- Fixed in:
- 2.0
- Disclosed:
- Jan 5, 2013
Spam Free WordPress <= 1.9.3 - IP Protection Bypass
medium
The Spam Free WordPress plugin for WordPress is vulnerable to IP Protection Bypass in versions up to, and including, 1.9.3 via the sfw_comment_post_authentication() function due to the fact that the plugin relies on a value that can be user-supplied ('comment_ip' parameter) for the IP address that is checked against th...
- CVSS:
- 5.3
- Affected:
- up to 1.9.3
- Fixed in:
- 2.0
- Disclosed:
- Jan 5, 2013
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database