Missing Authorization Vulnerability in Maspik Plugin for WordPress
CVE-2025-9979
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2025
What is CVE-2025-9979?
The Maspik plugin for WordPress suffers from a security flaw due to insufficient capability checks in the Maspik_spamlog_download_csv function. As a result, authenticated users with subscriber-level permissions can export and download the spam log database. This database may contain sensitive information, including false positives and legitimate yet misclassified submissions. Website owners using the affected versions should update to the latest version to mitigate the risk of unauthorized data access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Maspik β Ultimate Spam Protection * <= 2.5.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved