plugin

Spam Free Wordpress Vulnerabilities

2 known security issues reported for the Spam Free Wordpress WordPress plugin. Most recent disclosed Jan 5, 2013.

1 high 1 medium

Running Spam Free Wordpress on your site? Check whether your installed version is affected.

Scan your site free

Spam Free WordPress <= 1.9.3 - Full Path Disclosure

high

The Spam Free WordPress plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 1.9.3 via various files. This makes it possible for unauthenticated attackers to extract sensitive data which consists of full application path details that can be used to exploit additional vulnerabilit...

CVSS:
7.5
Affected:
up to 1.9.3
Fixed in:
2.0
Disclosed:
Jan 5, 2013

Spam Free WordPress <= 1.9.3 - IP Protection Bypass

medium

The Spam Free WordPress plugin for WordPress is vulnerable to IP Protection Bypass in versions up to, and including, 1.9.3 via the sfw_comment_post_authentication() function due to the fact that the plugin relies on a value that can be user-supplied ('comment_ip' parameter) for the IP address that is checked against th...

CVSS:
5.3
Affected:
up to 1.9.3
Fixed in:
2.0
Disclosed:
Jan 5, 2013

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database