Extension WordPress

Vulnérabilités Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

Cette page rassemble les failles publiées pour Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
3Critiques
10Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

10 fiches

CVE-2025-9376 Moyenne · 6,5
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 – Insufficient Authorization to Unauthenticated Blocklist Bypass

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions…

Versions affectées

*-11.58

Correctif

11.59

Publication

27/08/2025

CVE-2024-4355 Moyenne · 4,3
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.23 – Missing Authorization to Information Expsoure

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions…

Versions affectées

*-10.23

Correctif

10.24

Publication

29/05/2024

CVE-2023-32496 Moyenne · 4,4
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

StopBadBots <= 7.31 – Authenticated (Administrator+) Stored Cross-Site Scripting

The StopBadBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-7.31

Correctif

7.32

Publication

09/05/2023

CVE-2022-3883 Moyenne · 6,5
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

StopBadBots <= 7.23 – Missing Authorization to Arbitrary Plugin Installation

The StopBadBots plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stopbadbots_install_plugin() function in versions up to, and including, 7.23. This makes it possible for authenticated attackers with minimal permission, such…

Versions affectées

*-7.23

Correctif

7.24

Publication

18/11/2022

CVE-2022-0949 Critique · 9,8
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

WP Block and Stop Bad Bots <= 6.92 – SQL Injection

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint…

Versions affectées

[*, 6.930)

Correctif

6.930

Publication

16/03/2022

CVE-2021-24863 Critique · 9,8
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.67 – Unauthenticated SQL Injection

The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it,…

Versions affectées

[*, 6.67)

Correctif

6.67

Publication

15/11/2021

Vulnérabilité Moyenne · 6,1
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 6.61 – Reflected Cross-Site Scripting

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 6.61 due to insufficient…

Versions affectées

*-6.61

Correctif

6.62

Publication

25/08/2021

Vulnérabilité Moyenne · 6,1
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection < 6.6.7 – Reflected Cross-Site Scripting

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 6.6.7 due to insufficient input sanitization and…

Versions affectées

[*, 6.67)

Correctif

6.67

Publication

25/08/2021

CVE-2021-24727 Élevée · 8,8
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection

WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.60 – Authenticated SQL Injection

The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections.

Versions affectées

[*, 6.60)

Correctif

6.60

Publication

06/08/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités