← back to popular plugins
wordfence / plugin · contact-forms-anti-spam
Maspik – Ultimate Spam Protection
contact-forms-anti-spam
total installs
30,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
—
patched
2
unpatched
0
avg time to patch
—
vulnerabilities
(2)
Maspik <= 2.5.6 - Authenticated (Subscriber+) Missing Authorization to Spam Log Export
medium
✓ patched
The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.
Maspik <= 2.5.6 - Cross-Site Request Forgery
medium
✓ patched
cve id
CVE-2025-9888 ↗
cvss score
4.3
cwe
CWE-352: Cross-Site Request Forgery (CSRF)
published
Sep 9, 2025
The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.