Missing Authorization Vulnerability in Maspik Plugin for WordPress
CVE-2025-9979
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2025
What is CVE-2025-9979?
The Maspik plugin for WordPress suffers from a security flaw due to insufficient capability checks in the Maspik_spamlog_download_csv function. As a result, authenticated users with subscriber-level permissions can export and download the spam log database. This database may contain sensitive information, including false positives and legitimate yet misclassified submissions. Website owners using the affected versions should update to the latest version to mitigate the risk of unauthorized data access.
Affected Version(s)
Maspik – Ultimate Spam Protection * <= 2.5.6