Information disclosure via unconditional error logging

The plugin writes error messages to server log files even on production websites. If someone has access to read those log files, they could see internal details about your WordPress site when errors occur.

This vulnerability affects the following application versions:

  • Disable Comments – Remove Comments & Stop Spam 2.5.3

SQL injection in the comment meta of the post types

SQL injection is possible due to not properly preparing the SQL statements while updating and removing comments and meta comments.

This vulnerability affects the following application versions:

  • Disable Comments – Remove Comments & Stop Spam 2.1.0
  • Disable Comments – Remove Comments & Stop Spam 2.1.1
  • Disable Comments – Remove Comments & Stop Spam 2.1.2
  • Disable Comments – Remove Comments & Stop Spam 2.2.0
  • Disable Comments – Remove Comments & Stop Spam 2.2.1
  • Disable Comments – Remove Comments & Stop Spam 2.2.2
  • Disable Comments – Remove Comments & Stop Spam 2.2.3
  • Disable Comments – Remove Comments & Stop Spam 2.2.4
  • Disable Comments – Remove Comments & Stop Spam 2.3.0
  • Disable Comments – Remove Comments & Stop Spam 2.3.1
  • Disable Comments – Remove Comments & Stop Spam 2.3.2
  • Disable Comments – Remove Comments & Stop Spam 2.3.3
  • Disable Comments – Remove Comments & Stop Spam 2.3.4
  • Disable Comments – Remove Comments & Stop Spam 2.3.5
  • Disable Comments – Remove Comments & Stop Spam 2.3.6
  • Disable Comments – Remove Comments & Stop Spam 2.4.0
  • Disable Comments – Remove Comments & Stop Spam 2.4.1