Peter’s Custom Anti-Spam
Peter’s Custom Anti-Spam has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for Peter’s Custom Anti-Spam has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Peter’s Custom Anti-Spam is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.
CVE-2023-45759Peter’s Custom Anti-Spam <= 3.2.2 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Peter’s Custom Anti-Spam
Author
Peter
Stop a lot of spambots from polluting your site by making visitors identify a random word displayed as an image before commenting and optionally before registering. You can customize the pool of words to display. Features Toggle whether registered users need to enter the word Random font display No cookies required No JavaScript required Auto-generated audio for visually impaired users Easy-to-read No mapping of words from the code — words are used once or removed after 24 hours Reminder of what was entered if you get the word wrong Selective blocking of trackbacks, pingbacks Easy to translate Compatible with caching plugins Negatives Purposely no obscuring techniques so that the anti-spam word is easy to read The more people who use this plugin, the more motivation for spambots to target it Requirements GD Library and FreeType Library (There’s a diagnostic page to tell you whether you have them installed. If needed, just ask your web host to install them!) WordPress 3.2 or higher Translations ru_RU translation by koc sk_SK translation by Patrik Žec (PATWIST) of http://patwist.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C