Zero Spam for WordPress <= 5.7.11 - Unauthenticated Login Protection Bypass via 'woocommerce-login-nonce' and 'pp_current_url' Parameters

Medium 5.3 CWE-693Fixed in 5.7.12
ID
WPSEC-2026-0474
Plugin
Zero Spam for WordPress (zero-spam)
Affected
from 5.2.14 before 5.7.12
Remediation
Update to 5.7.12 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-693
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
Zero Spam for WordPress on WPSec AttackSurface
Fix released
Published

Description

The Zero Spam for WordPress plugin for WordPress is vulnerable to a login protection bypass in versions 5.2.14 up to, and including, 5.7.11. This is due to the plugin skipping its login checks whenever a login request contained a non-empty 'woocommerce-login-nonce' field (or, since 5.5.0, a 'pp_current_url' field), without verifying the nonce, checking that WooCommerce or ProfilePress was active, or limiting the exception to those plugins' own login forms. This makes it possible for unauthenticated attackers to add one of these fields to a wp-login.php request and bypass the honeypot and David Walsh checks that the plugin's 'Protect Login Attempts' setting uses to stop automated login attempts.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0