Maspik <= 2.5.6 - Authenticated (Subscriber+) Missing Authorization to Spam Log Export

2025-09-09 17:27
Dmitrii Ignatyev

Strategic Overview

Status
Patched in 2.5.7
Affected Version<= 2.5.6
CVSS4.3Medium
CVECVE-2025-9979
View all Maspik – Ultimate Spam Protection vulnerabilities

Vulnerability Overview

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

Technical Analysis

REMEDIATION: Update to version 2.5.7, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C