Extension WordPress
Vulnérabilités Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection
Cette page rassemble les failles publiées pour Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection
10 fiches
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 – Insufficient Authorization to Unauthenticated Blocklist Bypass
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions…
*-11.58
11.59
27/08/2025
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.23 – Missing Authorization to Information Expsoure
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions…
*-10.23
10.24
29/05/2024
StopBadBots <= 7.31 – Authenticated (Administrator+) Stored Cross-Site Scripting
The StopBadBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-7.31
7.32
09/05/2023
StopBadBots <= 7.23 – Missing Authorization to Arbitrary Plugin Installation
The StopBadBots plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stopbadbots_install_plugin() function in versions up to, and including, 7.23. This makes it possible for authenticated attackers with minimal permission, such…
*-7.23
7.24
18/11/2022
WP Block and Stop Bad Bots <= 6.92 – SQL Injection
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint…
[*, 6.930)
6.930
16/03/2022
WP Block and Stop Bad Bots <= 6.88 – SQL Injection
The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue
[*, 6.88)
6.90
08/03/2022
WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.67 – Unauthenticated SQL Injection
The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it,…
[*, 6.67)
6.67
15/11/2021
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 6.61 – Reflected Cross-Site Scripting
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 6.61 due to insufficient…
*-6.61
6.62
25/08/2021
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection < 6.6.7 – Reflected Cross-Site Scripting
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 6.6.7 due to insufficient input sanitization and…
[*, 6.67)
6.67
25/08/2021
WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.60 – Authenticated SQL Injection
The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections.
[*, 6.60)
6.60
06/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.