CVE-2023-48271
WordPress Maspik – Spam Blacklist plugin <= 0.10.3 - IP Filtering Bypass vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authentication Bypass by Spoofing vulnerability in yonifre Maspik – Spam blacklist allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maspik – Spam blacklist: from n/a through 0.10.3.
Vulnerabilidad de omisión de autenticación mediante suplantación de identidad en yonifre Maspik – Spam blacklist permite acceder a funciones no restringidas adecuadamente por las ACL. Este problema afecta a Maspik – Spam blacklist: desde n/a hasta 0.10.3.
The Maspik – Spam Blacklist plugin for WordPress is vulnerable to IP Filtering Bypass in all versions up to, and including, 0.10.3 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to bypass IP-based restrictions.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-11-13 CVE Reserved
- 2023-11-21 CVE Published
- 2024-06-06 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-290: Authentication Bypass by Spoofing
- CWE-348: Use of Less Trusted Source
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/contact-forms-anti-spam/wordpress-maspik-spam-blacklist-plugin-0-9-2-ip-filtering-bypass-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Contact Forms Anti Spam Search vendor "Contact Forms Anti Spam" | Contact Forms Anti Spam Search vendor "Contact Forms Anti Spam" for product "Contact Forms Anti Spam" | >= 0.0.0 <= 0.10.3 Search vendor "Contact Forms Anti Spam" for product "Contact Forms Anti Spam" and version " >= 0.0.0 <= 0.10.3" | en |
Affected
|