The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.23. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data.
History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data. The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.23. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data.
Title Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.24 - Missing Authorization to Information Expsoure Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.23 - Missing Authorization to Information Expsoure
Weaknesses CWE-862
References

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00385}

epss

{'score': 0.00294}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-05-30T08:30:14.013Z

Updated: 2026-04-08T17:21:25.789Z

Reserved: 2024-04-30T17:28:00.329Z

Link: CVE-2024-4355

cve-icon Vulnrichment

Updated: 2024-08-01T20:40:47.127Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-30T09:15:09.790

Modified: 2026-04-08T19:21:35.203

Link: CVE-2024-4355

cve-icon Redhat

No data.