{
 "id": "WPSEC-2026-0474",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0474/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0474/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0474/index.md",
 "title": "Zero Spam for WordPress <= 5.7.11 - Unauthenticated Login Protection Bypass via 'woocommerce-login-nonce' and 'pp_current_url' Parameters",
 "description": "The Zero Spam for WordPress plugin for WordPress is vulnerable to a login protection bypass in versions 5.2.14 up to, and including, 5.7.11. This is due to the plugin skipping its login checks whenever a login request contained a non-empty 'woocommerce-login-nonce' field (or, since 5.5.0, a 'pp_current_url' field), without verifying the nonce, checking that WooCommerce or ProfilePress was active, or limiting the exception to those plugins' own login forms. This makes it possible for unauthenticated attackers to add one of these fields to a wp-login.php request and bypass the honeypot and David Walsh checks that the plugin's 'Protect Login Attempts' setting uses to stop automated login attempts.",
 "plugin": {
  "slug": "zero-spam",
  "name": "Zero Spam for WordPress",
  "full_name": "Zero Spam for WordPress",
  "wordpress_org": "https://wordpress.org/plugins/zero-spam/",
  "advisories_url": "https://wpsec.com/vuln/plugin/zero-spam/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/zero-spam"
 },
 "type": "BYPASS",
 "cwe": [
  "CWE-693"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "5.2.14",
    "from_inclusive": true,
    "to": "5.7.12",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 5.2.14 before 5.7.12"
  ]
 },
 "introduced_in": "5.2.14",
 "fixed_in": "5.7.12",
 "remediation": "Update to 5.7.12 or later.",
 "fix_released": "2026-10-04T19:48:20+00:00",
 "published": "2026-10-06T19:43:53+00:00",
 "updated": "2026-10-06T19:05:42.020997+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0474/",
  "https://plugins.svn.wordpress.org/zero-spam/tags/5.7.12/",
  "https://wordpress.org/plugins/zero-spam/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/zero-spam",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-06"
 }
}