vulnerability

WordPress Plugin: contact-forms-anti-spam: CVE-2025-9979: Missing Authorization

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Sep 9, 2025
Added
Sep 10, 2025
Modified
Sep 11, 2025

Description

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

Solution

contact-forms-anti-spam-plugin-cve-2025-9979
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.