Description
Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper spam-stopper allows Stored XSS.This issue affects spam-stopper: from n/a through <= 3.1.3.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A CSRF flaw in the Mike spam‑stopper plugin permits an attacker to submit a request that stores malicious script code in the database, resulting in stored XSS when any user views the affected content. The attacker could inject arbitrary JavaScript that executes in the context of the victims’ browsers, leading to theft of session cookies, defacement, or redirection to malicious sites. The weakness is identified as CWE‑352, but the impact manifests as a stored XSS vulnerability.

Affected Systems

The vulnerability affects all installations of Mike’s spam‑stopper plugin with version 3.1.3 or earlier. This includes every WordPress site that has not yet upgraded beyond 3.1.3. No specific WordPress core versions are mentioned, but any site running the affected plugin is at risk.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high impact. The EPSS score of less than 1% shows that the overall exploitation probability is very low at present, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw is a CSRF that leads to stored XSS, an attacker can trigger it with a single forged request and the malicious payload persists until deleted. The attack path requires the attacker to convince a user with sufficient privileges—such as an administrator or editor—to visit a crafted URL or submit a forged form. The CSRF vector indicates that exploitation can occur over the network in a typical user session, potentially making the vulnerability more difficult to mitigate via network controls alone.

Generated by OpenCVE AI on May 2, 2026 at 02:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade spam‑stopper to a version newer than 3.1.3 when the fix becomes available.
  • If an upgrade cannot be performed immediately, remove the plugin entirely.
  • Restrict the ability to use plugin configuration options to administrators only, and monitor for unvalidated JavaScript input.

Generated by OpenCVE AI on May 2, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11584 Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper allows Stored XSS. This issue affects spam-stopper: from n/a through 3.1.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper allows Stored XSS. This issue affects spam-stopper: from n/a through 3.1.3. Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper spam-stopper allows Stored XSS.This issue affects spam-stopper: from n/a through <= 3.1.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper allows Stored XSS. This issue affects spam-stopper: from n/a through 3.1.3.
Title WordPress spam-stopper plugin <= 3.1.3 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:30.554Z

Reserved: 2025-04-16T06:22:58.198Z

Link: CVE-2025-39414

cve-icon Vulnrichment

Updated: 2025-04-17T15:49:35.516Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:51.030

Modified: 2026-04-23T15:29:30.533

Link: CVE-2025-39414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:15:31Z

Weaknesses