CVE-2026-81763: WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Throws SPAM Away pluginto a version that resolves this vulnerability.Fixed in 3.9
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is exploitable without authentication, so an attacker does not need a WordPress account or existing access to the site. Network-reachable sites using an affected plugin version are exposed.
Which installations are affected?
WordPress sites running Throws SPAM Away version 3.8.2 or earlier are affected. The provided information does not identify any configuration prerequisite or mitigation setting.
What is the potential impact of successful exploitation?
The vulnerability is SQL injection with critical severity. The supplied vector indicates high confidentiality impact, no integrity impact, and low availability impact.