Description
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Published: 2026-08-31
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated SQL injection vulnerability exists in the Throws SPAM Away plugin versions 3.8.2 and earlier. The flaw allows attackers to inject arbitrary SQL statements through user input fields, potentially enabling data exfiltration, modification, or total compromise of the WordPress database. If exploited, this can lead to loss of confidentiality, integrity, and availability, and may provide a foothold for further lateral or privilege‑elevated attacks.

Affected Systems

WordPress sites running the Throws SPAM Away plugin developed by ウェブ屋のさとーさん are affected. Versions up to and including 3.8.2 contain the vulnerability; upgrading to at least 3.9 removes the flaw. Site administrators should verify the installed plugin version and apply the update promptly.

Risk and Exploitability

The CVSS score of 9.3 signals critical severity, and because the vulnerability is unauthenticated it can be leveraged by any internet‑connected attacker. EPSS data is not available, but the absence from the CISA KEV list does not mitigate the risk. The most likely attack vector involves sending specially crafted HTTP requests to the plugin’s endpoints, with no prerequisites beyond accessibility. The combination of high severity and easy exploitation makes this a high‑priority target for attackers.

Generated by OpenCVE AI on August 31, 2026 at 21:55 UTC.

Remediation

Vendor Solution

Update the WordPress Throws SPAM Away Plugin to the latest available version (at least 3.9).


OpenCVE Recommended Actions

  • Update the Throws SPAM Away plugin to version 3.9 or newer to remove the SQL injection flaw.
  • Disable the plugin on any WordPress installation where its functionality is not required to eliminate the attack surface.
  • Deploy a web application firewall or security plugin that filters SQL injection patterns and monitors suspicious activity around the plugin’s endpoints.

Generated by OpenCVE AI on August 31, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
ウェブ屋のさとーさん
ウェブ屋のさとーさん throws Spam Away
Vendors & Products Wordpress
Wordpress wordpress
ウェブ屋のさとーさん
ウェブ屋のさとーさん throws Spam Away

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Title WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
ウェブ屋のさとーさん Throws Spam Away
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-01T18:12:24.672Z

Reserved: 2026-08-27T12:22:09.413Z

Link: CVE-2026-81763

cve-icon Vulnrichment

Updated: 2026-09-01T18:12:21.819Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T21:17:51.293

Modified: 2026-09-01T20:48:22.513

Link: CVE-2026-81763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:16:22Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')