Sceawere
Vulnerability Detail
CVE-2026-105057UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zero Spam Unauthenticated Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 16h ago
- Vendor
- Ben Marshall
- Product
- Zero Spam
- Attack Type
- CWE-290 Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-06T09:17:40.133Z",
"pubdate": "2026-10-06T09:17:40.133Z",
"executiveSummary": "The Zero Spam plugin for WordPress is susceptible to an unauthenticated bypass vulnerability affecting all versions up to and including 5.7.11.\nThis security flaw stems from insufficient access control enforcement, allowing remote, unauthenticated attackers to circumvent intended plugin restrictions.\nThe vulnerability poses a significant risk to site integrity and security configurations managed by the plugin, as it facilitates unauthorized interaction with protected endpoints.\nBecause the flaw does not require prior authentication or elevated privileges, it is highly accessible to malicious actors targeting WordPress environments.\nSuccessful exploitation could lead to unauthorized configuration changes, bypass of spam protection mechanisms, or potential exposure of sensitive data depending on the specific functionality exposed through the bypass.\nImmediate action is required to address this exposure and prevent potential exploitation of the plugin's security functions.",
"technicalDetails": "The vulnerability is rooted in a failure of the Zero Spam plugin to properly validate authentication and authorization tokens during critical request handling processes.\nIn affected versions (<= 5.7.11), the plugin implementation fails to perform adequate checks on incoming requests to its sensitive endpoints, effectively permitting unauthenticated users to interact with functions intended only for authorized administrators.\nThe root cause lies in the improper use or omission of nonce verification and capability checks within the plugin's request handling logic. Specifically, the mechanisms intended to guard against unauthorized access are either absent or improperly initialized during the request lifecycle.\nAn attacker can exploit this by crafting malicious HTTP requests directed at the vulnerable endpoints. Because the plugin does not verify the authenticity of the requester, it processes these requests as if they originated from a trusted source.\nThe attack flow proceeds as follows: 1. The attacker identifies the vulnerable endpoint within the Zero Spam plugin structure. 2. The attacker crafts a request, such as a GET or POST request, targeting this endpoint. 3. Due to the lack of restrictive checks, the server fails to challenge the request for authentication or privilege level. 4. The plugin logic executes the requested action on behalf of the unauthenticated user.\nThe scope of impact is contingent upon the functions exposed by the bypass. If the bypassed endpoint controls security settings, an attacker could potentially disable protection features, modify filtering rules, or interact with backend administrative logic. This effectively invalidates the security objectives of the Zero Spam plugin, potentially exposing the site to spam, automated attacks, or other unauthorized activities that the plugin was designed to prevent.\nSince the vulnerability is exploitable remotely over the network without any user interaction or pre-existing credentials, the risk is elevated. The vulnerability affects the core functionality responsible for mediating security requests, thereby rendering any site running version 5.7.11 or lower exposed until the underlying access control logic is corrected."
}