Input validation vulnerability in Math Comment Spam Protection 2.1

The Math Comment Spam Protection 2.1 and earlier plugin for WordPress had multiple security flaws that allowed remote attackers to perform certain administrative actions on the website. These attacks were done by manipulating the mcsp_opt_msg_no_answer and mcsp_opt_msg_wrong_answer parameters on the wp-admin/options-general.php page.

Detected in:

Math Comment Spam Protection open vulnerable versions: >= * <= 2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.