Zero Spam for WordPress <= 5.7.11 - Unauthenticated Login Protection Bypass via 'woocommerce-login-nonce' and 'pp_current_url' Parameters
- ID
- WPSEC-2026-0474
- Plugin
- Zero Spam for WordPress (zero-spam)
- Affected
- from 5.2.14 before 5.7.12
- Remediation
- Update to 5.7.12 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-693
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- Zero Spam for WordPress on WPSec AttackSurface
- Fix released
- Published
Description
The Zero Spam for WordPress plugin for WordPress is vulnerable to a login protection bypass in versions 5.2.14 up to, and including, 5.7.11. This is due to the plugin skipping its login checks whenever a login request contained a non-empty 'woocommerce-login-nonce' field (or, since 5.5.0, a 'pp_current_url' field), without verifying the nonce, checking that WooCommerce or ProfilePress was active, or limiting the exception to those plugins' own login forms. This makes it possible for unauthenticated attackers to add one of these fields to a wp-login.php request and bypass the honeypot and David Walsh checks that the plugin's 'Protect Login Attempts' setting uses to stop automated login attempts.
References
- https://wpsec.com/vuln/WPSEC-2026-0474/
- https://plugins.svn.wordpress.org/zero-spam/tags/5.7.12/
- https://wordpress.org/plugins/zero-spam/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS