Access violation vulnerability in Spam Free WordPress 1.9.3

. The Spam Free WordPress plugin for WordPress is vulnerable to a security issue in versions up to and including 1.9.3. This issue allows unauthenticated attackers to bypass the comment restrictions which are meant to protect the website. This is because the plugin uses a value (comment_ip parameter) that can be supplied by the user to check the IP address against the blocklist, rather than using a secure method.

Detected in:

Spam Free WordPress open vulnerable versions: >= * <= 1.9.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.