Stop Spammers Classic
Stop Spammers Classic has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 9 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 5 of the records (56%). Other recurring categories include Cross-Site Request Forgery (CSRF), Deserialization Of Untrusted Data.
Every one of the 9 issues recorded for Stop Spammers Classic has a vendor fix available, so running the current release closes all known holes.
8 independent researchers contributed these findings, most of them (2) reported by Erwan LR. Stop Spammers Classic is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-4120Stop Spammers Security <= 2022.5 - Unauthenticated PHP Object Injection
Read the full analysisVulnerability Records

Stop Spammers Classic
Author
Web Guy
💬 Ask Question | 📧 Email Me Stop Spammers is now Dam Spam. Switching is easy. All of your settings migrate over automatically in the background. Stop Spammers Classic is legacy code that will receive security patches only moving forward. 🥪 Buy me a sandwich to help preserve Stop Spammers Classic or further project development in Dam Spam if you rely on either of them.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C