CVE-2025-9979

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.
Configurations

No configuration.

History

10 Sep 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-10 07:15

Updated : 2025-09-11 17:14


NVD link : CVE-2025-9979

Mitre link : CVE-2025-9979

CVE.ORG link : CVE-2025-9979


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization