Sceawere

Vulnerability Detail

CVE-2026-105057UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zero Spam Unauthenticated Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
16h ago
Vendor
Ben Marshall
Product
Zero Spam
Attack Type
CWE-290 Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-06T09:17:40.133Z",
  "pubdate": "2026-10-06T09:17:40.133Z",
  "executiveSummary": "The Zero Spam plugin for WordPress is susceptible to an unauthenticated bypass vulnerability affecting all versions up to and including 5.7.11.\nThis security flaw stems from insufficient access control enforcement, allowing remote, unauthenticated attackers to circumvent intended plugin restrictions.\nThe vulnerability poses a significant risk to site integrity and security configurations managed by the plugin, as it facilitates unauthorized interaction with protected endpoints.\nBecause the flaw does not require prior authentication or elevated privileges, it is highly accessible to malicious actors targeting WordPress environments.\nSuccessful exploitation could lead to unauthorized configuration changes, bypass of spam protection mechanisms, or potential exposure of sensitive data depending on the specific functionality exposed through the bypass.\nImmediate action is required to address this exposure and prevent potential exploitation of the plugin's security functions.",
  "technicalDetails": "The vulnerability is rooted in a failure of the Zero Spam plugin to properly validate authentication and authorization tokens during critical request handling processes.\nIn affected versions (<= 5.7.11), the plugin implementation fails to perform adequate checks on incoming requests to its sensitive endpoints, effectively permitting unauthenticated users to interact with functions intended only for authorized administrators.\nThe root cause lies in the improper use or omission of nonce verification and capability checks within the plugin's request handling logic. Specifically, the mechanisms intended to guard against unauthorized access are either absent or improperly initialized during the request lifecycle.\nAn attacker can exploit this by crafting malicious HTTP requests directed at the vulnerable endpoints. Because the plugin does not verify the authenticity of the requester, it processes these requests as if they originated from a trusted source.\nThe attack flow proceeds as follows: 1. The attacker identifies the vulnerable endpoint within the Zero Spam plugin structure. 2. The attacker crafts a request, such as a GET or POST request, targeting this endpoint. 3. Due to the lack of restrictive checks, the server fails to challenge the request for authentication or privilege level. 4. The plugin logic executes the requested action on behalf of the unauthenticated user.\nThe scope of impact is contingent upon the functions exposed by the bypass. If the bypassed endpoint controls security settings, an attacker could potentially disable protection features, modify filtering rules, or interact with backend administrative logic. This effectively invalidates the security objectives of the Zero Spam plugin, potentially exposing the site to spam, automated attacks, or other unauthorized activities that the plugin was designed to prevent.\nSince the vulnerability is exploitable remotely over the network without any user interaction or pre-existing credentials, the risk is elevated. The vulnerability affects the core functionality responsible for mediating security requests, thereby rendering any site running version 5.7.11 or lower exposed until the underlying access control logic is corrected."
}
CVE-2026-105057: Zero Spam Unauthenticated Bypass Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere