Spam Free WordPress <= 1.9.3 - IP Protection Bypass

2013-01-05 00:00
Akastep

Strategic Overview

Status
Patched in 2.0
Affected PluginSpam Free WordPress
Affected Version<= 1.9.3
CVSS5.3Medium
CVEN/A
View all Spam Free WordPress vulnerabilities

Vulnerability Overview

The Spam Free WordPress plugin for WordPress is vulnerable to IP Protection Bypass in versions up to, and including, 1.9.3 via the sfw_comment_post_authentication() function due to the fact that the plugin relies on a value that can be user-supplied ('comment_ip' parameter) for the IP address that is checked against the blocklist. This makes it possible for unauthenticated attackers to bypass comment restrictions

Technical Analysis

REMEDIATION: Update to version 2.0, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C