CVE-2022-4120

CVE-2022-4120: Stop Spammers Security < 2022.6 - Unauthenticated PHP Object Injection

Vendor Unknown
Product Stop Spammers Security | Block Spam Users, Comments, Forms
Published December 26, 2022
Last update April 14, 2025

CVSS base score

What the vulnerability does

01Description

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain

Key dates

02Disclosure timeline

December 26, 2022 CVE published
April 14, 2025 Record updated