关键漏洞信息 漏洞名称: Stop Spammers Classic <= 2026.1 - Cross-Site Request Forgery via Email Allowlist CVE: CVE-2025-14795 CVSS: 4.3 (Medium) 公开发布日期: January 27, 2026 最近更新日期: January 28, 2026 研究者: JoanClarke2 描述 The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2026.1. This is due to missing nonce validation in the ss_addtoallowlist class. This makes it possible for unauthenticated attackers to add arbitrary email addresses to the spam allowlist via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The vulnerability was partially patched in version 2026.1. 漏洞详情 软件类型: Plugin 软件标识: stop-spammer-registrations-plugin 是否已修复: Yes 修复建议: 更新至版本2026.2,或更新的已修复版本 受影响版本: <= 2026.1 修复版本: 2026.2