The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible for unauthenticated attackers to bypass blocklists, rate limits, and other plugin functionality.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 28 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 28 Aug 2025 12:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible for unauthenticated attackers to bypass blocklists, rate limits, and other plugin functionality. | |
| Title | Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 - Insufficient Authorization to Unauthenticated Blocklist Bypass | |
| Weaknesses | CWE-863 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-28T11:16:21.743Z
Updated: 2025-08-28T14:48:14.973Z
Reserved: 2025-08-22T23:42:07.806Z
Link: CVE-2025-9376
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-28T13:35:12.977Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-08-28T12:15:39.280
Modified: 2025-08-29T16:24:09.860
Link: CVE-2025-9376
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow