User Spam Remover

User Spam Remover has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

2 independent researchers contributed these findings, one record each. User Spam Remover is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all User Spam Remover vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2025-62735

User Spam Remover <= 1.1 - Unauthenticated Information Exposure

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.1

User Spam Remover

Joel

Author

Joel

4.1(18)
82/100
Last Updated
2024-03-03 (3y ago)
Active Installs
1,000+
Downloads
57,131
Requires WP
3.9+
Requires PHP
0+
Tested up to
WP 6.4.10
Created
2010-08-27 (16y ago)

User Spam Remover is a plugin for WordPress that automatically removes spam user registrations and other old, never-used user accounts. It also blocks the notification e-mail that WordPress normally sends to the administrator whenever a new user registers (annoying when that registration is spam!) and logs it instead. The plugin adds a configuration panel so that all of these options can be turned on or off, and it logs and fully backs up all user accounts that it deletes, so that you can restore them if you need to. Features: Automatically deletes user registration spam and other orphaned, never-used accounts. Very simple, enable and go! Doesn’t interfere with the normal user registration process in any way. So, it doesn’t add captchas or activation or anything else — you’re free to use it alongside a plugin that does, if you like. Blocks notification e-mail that WordPress normally sends to the administrator every time a new user registers (instead, logs this event). Fully configurable, with grace period for new accounts and optional username whitelist. Fully logs all actions and backs up all user accounts that it deletes so that you can seamlessly restore them if you ever need to. Please see requirements and installation instructions below, or online in the WordPress support forum. For more information, please go to: https://lyncd.com/user-spam-remover/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C