CVE-2026-105057: WordPress Zero Spam plugin <= 5.7.11 - Bypass vulnerability vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
Affected Software
1 affected component
WordPress Zero Spam<=5.7.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Zero Spam pluginto a version that resolves this vulnerability.Fixed in 5.7.12
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can attempt to exploit this issue?
The vulnerability is remotely reachable over the network and requires no authentication or user interaction. The attack complexity is rated low.
2
Which installations are in scope?
The affected version range is WordPress Zero Spam versions 5.7.11 and earlier. The provided data does not identify a fixed version.
3
What is the stated security impact?
The CVSS vector indicates an integrity impact, with no stated confidentiality or availability impact. The severity is medium, with a CVSS score of 5.3.