Zero Spam for WordPress [zero-spam] < 5.5.7
unknown
[en] Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.7
- Disclosed:
- May 17, 2024
CVE-2024-32521 on NVD →
Zero Spam <= 5.5.6 - Spam Protection Bypass
medium
The Zero Spam for WordPress plugin for WordPress is vulnerable to spam protection bypass in all versions up to, and including, 5.5.6.. This makes it possible for unauthenticated attackers to bypass spam protections.
- CVSS:
- 5.3
- Affected:
- up to 5.5.6
- Fixed in:
- 5.5.7
- Disclosed:
- Apr 15, 2024
CVE-2024-32521 on NVD →
Zero Spam for WordPress [zero-spam] < 5.4.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects Zero Spam for WordPress: from n/a through 5.4.4.
- Affected:
- up to 5.4.5
- Fixed in:
- 5.4.5
- Disclosed:
- Nov 3, 2023
CVE-2023-32121 on NVD →
Zero Spam for WordPress [zero-spam] < 2.1.2
unknown
Update the plugin.
Werner Alsemgeest discovered and reported this SQL Injection vulnerability in WordPress Zero Spam Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 2.1.2.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 24, 2023
Zero Spam <= 5.4.4 - Authenticated (Administrator+) SQL Injection
high
The Zero Spam plugin for WordPress is vulnerable to SQL Injection parameter in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers , with administrator-level acc...
- CVSS:
- 7.2
- Affected:
- up to 5.4.4
- Fixed in:
- 5.4.5
- Disclosed:
- May 9, 2023
CVE-2023-32121 on NVD →
Zero Spam for WordPress <= 5.4.4 - Authenticated(Administrator+) SQL Injection
high
The Zero Spam for WordPress plugin is vulnerable to generic SQL Injection via the 'type', 'country', and 's' parameters in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentica...
- CVSS:
- 7.2
- Affected:
- up to 5.4.5
- Fixed in:
- 5.4.5
- Disclosed:
- May 8, 2023
Zero Spam for WordPress [zero-spam] < 5.4.5
unknown
The Zero Spam for WordPress plugin is vulnerable to generic SQL Injection via the 'type', 'country', and 's' parameters in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentica...
- Affected:
- up to 5.4.5
- Fixed in:
- 5.4.5
- Disclosed:
- May 8, 2023
Zero Spam for WordPress [zero-spam] < 5.2.10
unknown
Update the WordPress Zero Spam plugin to the latest available version (at least 5.2.10).
An unknown person discovered and reported this SQL Injection vulnerability in WordPress Zero Spam Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information...
- Affected:
- up to 5.2.10
- Fixed in:
- 5.2.10
- Disclosed:
- Jan 19, 2023
Zero Spam for WordPress [zero-spam] < 5.2.11
unknown
[en] The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection
- Affected:
- up to 5.2.11
- Fixed in:
- 5.2.11
- Disclosed:
- Mar 14, 2022
CVE-2022-0254 on NVD →
Zero Spam <= 5.2.10 - Admin+ SQL Injection
high
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection
- CVSS:
- 7.2
- Affected:
- up to 5.2.10
- Fixed in:
- 5.2.11
- Disclosed:
- Feb 18, 2022
CVE-2022-0254 on NVD →
Zero Spam for WordPress [zero-spam] < 5.2.10
unknown
SQL injection (SQLi) vulnerability discovered in WordPress Zero Spam plugin (versions <= 5.2.9).
- Affected:
- up to 5.2.10
- Fixed in:
- 5.2.10
- Disclosed:
- Jan 19, 2022
WordPress Zero Spam <= 2.1.1 - SQL Injection
critical
The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied Client-IP header parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to ap...
- CVSS:
- 9.8
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2.0
- Disclosed:
- Aug 24, 2016
Zero Spam for WordPress [zero-spam] < 2.1.2
unknown
This plugin is prone to a blind SQL injection vulnerability.
Update the plugin.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 24, 2016
Zero Spam for WordPress [zero-spam] < 2.2.0
unknown
The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied Client-IP header parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to ap...
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Aug 24, 2016
Zero Spam for WordPress [zero-spam] < 2.2.0
unknown
The WordPress Zero Spam WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
Zero Spam for WordPress [zero-spam] < 5.4.5
unknown
The plugin is vulnerable to SQL Injection parameter in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers , with administrator-level access and above, to append...
- Affected:
- up to 5.4.5
- Fixed in:
- 5.4.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database