# Zero Spam for WordPress <= 5.7.11 - Unauthenticated Login Protection Bypass via 'woocommerce-login-nonce' and 'pp_current_url' Parameters

- **ID:** WPSEC-2026-0474
- **Plugin:** Zero Spam for WordPress (`zero-spam`), https://wordpress.org/plugins/zero-spam/
- **Affected versions:** from 5.2.14 before 5.7.12
- **Fixed in:** 5.7.12 (Update to 5.7.12 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-693
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/zero-spam
- **Fix released:** 2026-10-04
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0474/

## Description

The Zero Spam for WordPress plugin for WordPress is vulnerable to a login protection bypass in versions 5.2.14 up to, and including, 5.7.11. This is due to the plugin skipping its login checks whenever a login request contained a non-empty 'woocommerce-login-nonce' field (or, since 5.5.0, a 'pp_current_url' field), without verifying the nonce, checking that WooCommerce or ProfilePress was active, or limiting the exception to those plugins' own login forms. This makes it possible for unauthenticated attackers to add one of these fields to a wp-login.php request and bypass the honeypot and David Walsh checks that the plugin's 'Protect Login Attempts' setting uses to stop automated login attempts.

## References

- https://wpsec.com/vuln/WPSEC-2026-0474/
- https://plugins.svn.wordpress.org/zero-spam/tags/5.7.12/
- https://wordpress.org/plugins/zero-spam/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0474/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
