CVE-2025-28872

Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Block Spam By Math Reloaded: from n/a through <= 2.2.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jwpegram:block_spam_by_math_reloaded:*:*:*:*:*:wordpress:*:*

History

01 Apr 2026, 17:19

Type Values Removed Values Added
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/block-spam-by-math-reloaded/vulnerability/wordpress-block-spam-by-math-reloaded-plugin-2-2-4-broken-access-control-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/block-spam-by-math-reloaded/vulnerability/wordpress-block-spam-by-math-reloaded-plugin-2-2-4-broken-access-control-vulnerability?_s_id=cve - Third Party Advisory
Summary (en) Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Block Spam By Math Reloaded: from n/a through 2.2.4. (en) Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Block Spam By Math Reloaded: from n/a through <= 2.2.4.
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 9.8

09 Apr 2025, 14:04

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de falta de autorización en jwpegram Block Spam By Math Reloaded permite acceder a funcionalidades no restringidas correctamente por las ACL. Este problema afecta a "Block Spam By Math Reloaded" desde n/d hasta la versión 2.2.4.
References () https://patchstack.com/database/wordpress/plugin/block-spam-by-math-reloaded/vulnerability/wordpress-block-spam-by-math-reloaded-plugin-2-2-4-broken-access-control-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/block-spam-by-math-reloaded/vulnerability/wordpress-block-spam-by-math-reloaded-plugin-2-2-4-broken-access-control-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:jwpegram:block_spam_by_math_reloaded:*:*:*:*:*:wordpress:*:*
First Time Jwpegram
Jwpegram block Spam By Math Reloaded

11 Mar 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 21:15

Updated : 2026-04-01 17:19


NVD link : CVE-2025-28872

Mitre link : CVE-2025-28872

CVE.ORG link : CVE-2025-28872


JSON object : View

Products Affected

jwpegram

  • block_spam_by_math_reloaded
CWE
CWE-862

Missing Authorization