CVE-2022-1663: Stop Spam Comments Project Stop Spam Comments
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request.
Affected products
- Stop Spam Comments Project Stop Spam Comments: up to and including 0.2.1.2
Published 2022-08-29. Last modified 2026-06-17.