Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue #135

Closed
ethicalhack3r opened this issue Aug 23, 2016 · 7 comments
Closed

Security Issue #135

ethicalhack3r opened this issue Aug 23, 2016 · 7 comments

Comments

@ethicalhack3r
Copy link

Hi,

The plugin has a serious security issue which was reported to us (wpvulndb.com). I have tried to contact two of the developers via email without success. Just found this Github repository now. WordPress are aware of the issue so they may have contacted you already.

Please email team at wpvulndb.com for the technical details.

Thanks,
Ryan

@bostonchic
Copy link

Hmm, I tried to delete it on three sites after deactivating and it won't uninstall.

@jaredatch
Copy link
Contributor

ping @bmarshall511

@janemanthorpe
Copy link

Hi,
I had the same issue but deleted via my control panel with Hostgator I am hosted with. Depending who you are hosted with , you need to go into the WP content area, then plugins and then find Zero spam plugin and delete all the files for your directory. Make sure first you have deactivated the plugin from your wordpress dashboard and done a backup first (just in case) Cheers Jane

@bostonchic
Copy link

Yes, I deleted via FTP... it's a shame that users who maintain their own site may not understand how to get rid of it. :(

@janemanthorpe
Copy link

Yes, you are right. Shame on the plugin creator just abandoning it.

@geckoseo
Copy link

?? It would be decent at the very least if the reason for the removal from the WP repo was explained on the authors website.

Instead we can apparently still download and use the plugin directly from here?

Is this not somewhat irresponsible? Why would anyone still allow a plugin with security holes in it to be downloaded?

thiagolcks added a commit to thiagolcks/wordpress-zero-spam that referenced this issue Nov 19, 2016
@thiagolcks
Copy link
Contributor

I've made a PR to fix this issue.

bmarshall511 pushed a commit that referenced this issue Nov 19, 2016
Validate the IP and sanitize a query - Issue #135
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants