Description
WordPress Plugin Spam Free WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass IP blocklist. WordPress Plugin Spam Free WordPress version 1.9.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.3 or latest
References
Related Vulnerabilities
Moodle Credentials Management Errors Vulnerability (CVE-2009-4304)
Joomla Cross-Site Request Forgery (CSRF) (CVE-2021-26033)
Oracle JRE CVE-2022-21271 Vulnerability (CVE-2022-21271)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4550)
WordPress Plugin TDO Mini Forms Arbitrary File Upload (0.13.9)