Impact
An unauthenticated SQL injection vulnerability exists in the Throws SPAM Away plugin versions 3.8.2 and earlier. The flaw allows attackers to inject arbitrary SQL statements through user input fields, potentially enabling data exfiltration, modification, or total compromise of the WordPress database. If exploited, this can lead to loss of confidentiality, integrity, and availability, and may provide a foothold for further lateral or privilege‑elevated attacks.
Affected Systems
WordPress sites running the Throws SPAM Away plugin developed by ウェブ屋のさとーさん are affected. Versions up to and including 3.8.2 contain the vulnerability; upgrading to at least 3.9 removes the flaw. Site administrators should verify the installed plugin version and apply the update promptly.
Risk and Exploitability
The CVSS score of 9.3 signals critical severity, and because the vulnerability is unauthenticated it can be leveraged by any internet‑connected attacker. EPSS data is not available, but the absence from the CISA KEV list does not mitigate the risk. The most likely attack vector involves sending specially crafted HTTP requests to the plugin’s endpoints, with no prerequisites beyond accessibility. The combination of high severity and easy exploitation makes this a high‑priority target for attackers.
OpenCVE Enrichment