Cross-Site Request Forgery Vulnerability in Anti-Spam Plugin for WordPress
CVE-2025-2935
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 June 2025
What is CVE-2025-2935?
The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is susceptible to a Cross-Site Request Forgery attack due to improper nonce validation in specific files. Attackers can exploit this vulnerability to delete pending comments or reactivate blocked users if they successfully trick an administrator into executing malicious requests. This issue is present in all versions up to and including 2024.7, highlighting the importance of securing your WordPress environment against unauthorized actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms * <= 2024.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved