VDB
Sign up
CRITICAL9.8

GHSA-pq2f-3fg3-rw99

SQL Injection in WordPress Zero Spam WordPress plugin

Quick fix

GHSA-pq2f-3fg3-rw99 — bmarshall511/wordpress_zero_spam: upgrade to the fixed version with the command below.

composer require bmarshall511/wordpress_zero_spam:^5.2.13

Details

The WordPress Zero Spam WordPress plugin before 5.2.13 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/bmarshall511/wordpress_zero_spam
Introduced in: 0Fixed in: 5.2.13
Fixcomposer require bmarshall511/wordpress_zero_spam:^5.2.13

References