top of page
perceptive_background_267k.jpg

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

Published:

31 augustus 2026 om 00:00:00

Alert date:

1 september 2026 om 00:05:29

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

A critical unauthenticated SQL injection vulnerability has been identified in the WordPress plugin 'Throws SPAM Away' affecting versions 3.8.2 and earlier. The vulnerability allows unauthenticated attackers to perform SQL injection attacks, potentially exposing sensitive database information or enabling further compromise of the WordPress site. The flaw is documented under CVE-2026-81763 and has been reported via both the NVD and Patchstack vulnerability databases. No authentication is required to exploit this vulnerability, making it particularly dangerous for unpatched installations. WordPress site administrators using this plugin are advised to update to a patched version immediately. The vulnerability was assigned a high severity rating. Details are available through the NVD and Patchstack advisory pages.

Technical details

Mitigation steps:

Affected products:

Throws SPAM Away WordPress Plugin <= 3.8.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page