vendor:
SpamBam
by:
Jose Palazon
5.5
CVSS
MEDIUM
Security Bypass
CWE
Product Name: SpamBam
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
SpamBam Security Bypass Vulnerability
The SpamBam plugin for WordPress is vulnerable to a security bypass issue. This is due to the fact that client-accessible data can be used to calculate verification keys. Attackers can exploit this vulnerability by submitting arbitrary form data via automated scripts and distribute spam.
Mitigation:
There is no fix for this vulnerability. It is a design flaw in the SpamBam plugin.