Input validation vulnerability in Zero Spam for WordPress 2.1.1

The WordPress Zero Spam plugin is vulnerable to a security flaw known as Blind SQL Injection in versions up to and including 2.1.1. This flaw is caused by the plugin failing to properly escape user-supplied Client-IP header parameters and not properly preparing existing SQL queries. This flaw can be exploited by unauthenticated attackers to append additional SQL queries to existing queries, which can be used to access sensitive information stored in the database.

Detected in:

Zero Spam for WordPress fixed vulnerable versions: >= * <= 2.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.