plugin

Zero Spam Vulnerabilities

16 known security issues reported for the Zero Spam WordPress plugin. Most recent disclosed May 17, 2024.

1 critical 3 high 1 medium

Running Zero Spam on your site? Check whether your installed version is affected.

Scan your site free

Zero Spam for WordPress [zero-spam] < 5.5.7

unknown

[en] Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.

Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
May 17, 2024

CVE-2024-32521 on NVD →

Zero Spam <= 5.5.6 - Spam Protection Bypass

medium

The Zero Spam for WordPress plugin for WordPress is vulnerable to spam protection bypass in all versions up to, and including, 5.5.6.. This makes it possible for unauthenticated attackers to bypass spam protections.

CVSS:
5.3
Affected:
up to 5.5.6
Fixed in:
5.5.7
Disclosed:
Apr 15, 2024

CVE-2024-32521 on NVD →

Zero Spam for WordPress [zero-spam] < 5.4.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects Zero Spam for WordPress: from n/a through 5.4.4.

Affected:
up to 5.4.5
Fixed in:
5.4.5
Disclosed:
Nov 3, 2023

CVE-2023-32121 on NVD →

Zero Spam for WordPress [zero-spam] < 2.1.2

unknown

Update the plugin. Werner Alsemgeest discovered and reported this SQL Injection vulnerability in WordPress Zero Spam Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 2.1.2.

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 24, 2023

Zero Spam <= 5.4.4 - Authenticated (Administrator+) SQL Injection

high

The Zero Spam plugin for WordPress is vulnerable to SQL Injection parameter in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers , with administrator-level acc...

CVSS:
7.2
Affected:
up to 5.4.4
Fixed in:
5.4.5
Disclosed:
May 9, 2023

CVE-2023-32121 on NVD →

Zero Spam for WordPress <= 5.4.4 - Authenticated(Administrator+) SQL Injection

high

The Zero Spam for WordPress plugin is vulnerable to generic SQL Injection via the 'type', 'country', and 's' parameters in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentica...

CVSS:
7.2
Affected:
up to 5.4.5
Fixed in:
5.4.5
Disclosed:
May 8, 2023

Zero Spam for WordPress [zero-spam] < 5.4.5

unknown

The Zero Spam for WordPress plugin is vulnerable to generic SQL Injection via the 'type', 'country', and 's' parameters in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentica...

Affected:
up to 5.4.5
Fixed in:
5.4.5
Disclosed:
May 8, 2023

Zero Spam for WordPress [zero-spam] < 5.2.10

unknown

Update the WordPress Zero Spam plugin to the latest available version (at least 5.2.10). An unknown person discovered and reported this SQL Injection vulnerability in WordPress Zero Spam Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information...

Affected:
up to 5.2.10
Fixed in:
5.2.10
Disclosed:
Jan 19, 2023

Zero Spam for WordPress [zero-spam] < 5.2.11

unknown

[en] The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

Affected:
up to 5.2.11
Fixed in:
5.2.11
Disclosed:
Mar 14, 2022

CVE-2022-0254 on NVD →

Zero Spam <= 5.2.10 - Admin+ SQL Injection

high

The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

CVSS:
7.2
Affected:
up to 5.2.10
Fixed in:
5.2.11
Disclosed:
Feb 18, 2022

CVE-2022-0254 on NVD →

Zero Spam for WordPress [zero-spam] < 5.2.10

unknown

SQL injection (SQLi) vulnerability discovered in WordPress Zero Spam plugin (versions <= 5.2.9).

Affected:
up to 5.2.10
Fixed in:
5.2.10
Disclosed:
Jan 19, 2022

WordPress Zero Spam <= 2.1.1 - SQL Injection

critical

The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied Client-IP header parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to ap...

CVSS:
9.8
Affected:
up to 2.1.1
Fixed in:
2.2.0
Disclosed:
Aug 24, 2016

Zero Spam for WordPress [zero-spam] < 2.1.2

unknown

This plugin is prone to a blind SQL injection vulnerability. Update the plugin.

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 24, 2016

Zero Spam for WordPress [zero-spam] < 2.2.0

unknown

The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied Client-IP header parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to ap...

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Aug 24, 2016

Zero Spam for WordPress [zero-spam] < 2.2.0

unknown

The WordPress Zero Spam WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.

Affected:
up to 2.2.0
Fixed in:
2.2.0

Zero Spam for WordPress [zero-spam] < 5.4.5

unknown

The plugin is vulnerable to SQL Injection parameter in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers , with administrator-level access and above, to append...

Affected:
up to 5.4.5
Fixed in:
5.4.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database