Zero Spam <= 5.5.6 - Spam Protection Bypass
2024-04-15 00:00
Brandon James Roldan (tomorrowisnew)Strategic Overview
StatusPatched in 5.5.7
Affected PluginZero Spam for WordPress
Affected Version
<= 5.5.6CVSS5.3Medium
CVE
CVE-2024-32521Vulnerability Overview
The Zero Spam for WordPress plugin for WordPress is vulnerable to spam protection bypass in all versions up to, and including, 5.5.6.. This makes it possible for unauthenticated attackers to bypass spam protections.
Technical Analysis
REMEDIATION: Update to version 5.5.7, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C