plugin

Stopbadbots Vulnerabilities

10 known security issues reported for the Stopbadbots WordPress plugin. Most recent disclosed Aug 27, 2025.

3 critical 1 high 6 medium

Running Stopbadbots on your site? Check whether your installed version is affected.

Scan your site free

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 - Insufficient Authorization to Unauthenticated Blocklist Bypass

medium

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible...

CVSS:
6.5
Affected:
up to 11.58
Fixed in:
11.59
Disclosed:
Aug 27, 2025

CVE-2025-9376 on NVD →

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.23 - Missing Authorization to Information Expsoure

medium

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.23. This makes it possible for authenticated attacke...

CVSS:
4.3
Affected:
up to 10.23
Fixed in:
10.24
Disclosed:
May 29, 2024

CVE-2024-4355 on NVD →

StopBadBots <= 7.31 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The StopBadBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web s...

CVSS:
4.4
Affected:
up to 7.31
Fixed in:
7.32
Disclosed:
May 9, 2023

CVE-2023-32496 on NVD →

StopBadBots <= 7.23 - Missing Authorization to Arbitrary Plugin Installation

medium

The StopBadBots plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stopbadbots_install_plugin() function in versions up to, and including, 7.23. This makes it possible for authenticated attackers with minimal permission, such as a subscriber, to install arbitrary plugins...

CVSS:
6.5
Affected:
up to 7.23
Fixed in:
7.24
Disclosed:
Nov 18, 2022

CVE-2022-3883 on NVD →

WP Block and Stop Bad Bots <= 6.92 - SQL Injection

critical

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL inje...

CVSS:
9.8
Affected:
up to 6.930
Fixed in:
6.930
Disclosed:
Mar 16, 2022

CVE-2022-0949 on NVD →

WP Block and Stop Bad Bots <= 6.88 - SQL Injection

critical

The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

CVSS:
9.8
Affected:
up to 6.88
Fixed in:
6.90
Disclosed:
Mar 8, 2022

CVE-2021-25070 on NVD →

WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.67 - Unauthenticated SQL Injection

critical

The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection

CVSS:
9.8
Affected:
up to 6.67
Fixed in:
6.67
Disclosed:
Nov 15, 2021

CVE-2021-24863 on NVD →

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection < 6.6.7 - Reflected Cross-Site Scripting

medium

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 6.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...

CVSS:
6.1
Affected:
up to 6.67
Fixed in:
6.67
Disclosed:
Aug 25, 2021

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 6.61 - Reflected Cross-Site Scripting

medium

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 6.61 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...

CVSS:
6.1
Affected:
up to 6.61
Fixed in:
6.62
Disclosed:
Aug 25, 2021

WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.60 - Authenticated SQL Injection

high

The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections.

CVSS:
8.8
Affected:
up to 6.60
Fixed in:
6.60
Disclosed:
Aug 6, 2021

CVE-2021-24727 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database