Description
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Published: 2026-08-31
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated SQL injection vulnerability exists in the Throws SPAM Away plugin versions 3.8.2 and earlier. The flaw allows attackers to inject arbitrary SQL statements through user input fields, potentially enabling data exfiltration, modification, or total compromise of the WordPress database. If exploited, this can lead to loss of confidentiality, integrity, and availability, and may provide a foothold for further lateral or privilege‑elevated attacks.

Affected Systems

WordPress sites running the Throws SPAM Away plugin developed by ウェブ屋のさとーさん are affected. Versions up to and including 3.8.2 contain the vulnerability; upgrading to at least 3.9 removes the flaw. Site administrators should verify the installed plugin version and apply the update promptly.

Risk and Exploitability

The CVSS score of 9.3 signals critical severity, and because the vulnerability is unauthenticated it can be leveraged by any internet‑connected attacker. EPSS data is not available, but the absence from the CISA KEV list does not mitigate the risk. The most likely attack vector involves sending specially crafted HTTP requests to the plugin’s endpoints, with no prerequisites beyond accessibility. The combination of high severity and easy exploitation makes this a high‑priority target for attackers.

Generated by OpenCVE AI on August 31, 2026 at 21:55 UTC.

Remediation

Vendor Solution

Update the WordPress Throws SPAM Away Plugin to the latest available version (at least 3.9).


OpenCVE Recommended Actions

  • Update the Throws SPAM Away plugin to version 3.9 or newer to remove the SQL injection flaw.
  • Disable the plugin on any WordPress installation where its functionality is not required to eliminate the attack surface.
  • Deploy a web application firewall or security plugin that filters SQL injection patterns and monitors suspicious activity around the plugin’s endpoints.

Generated by OpenCVE AI on August 31, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Title WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:30:49.036Z

Reserved: 2026-08-27T12:22:09.413Z

Link: CVE-2026-81763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:51.293

Modified: 2026-08-31T21:17:51.293

Link: CVE-2026-81763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')