Input validation vulnerability in Zero Spam for WordPress 5.4.5

() The Zero Spam for WordPress plugin, versions up to and including 5.4.4, is vulnerable to an attack called “generic SQL Injection”. This means it can be exploited by someone with administrator-level permissions. This attack could allow attackers to access sensitive information stored in the database. This vulnerability exists because of insufficient escaping of user-supplied parameters and lack of preparation on the existing SQL query.

Detected in:

Zero Spam for WordPress fixed vulnerable versions: >= * < 5.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.