
CVE-2025-14795 The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2026.1. This is due to missing nonce … https://www.cve.org/CVERecord?id=CVE-2025-14795
Post summary
The announcement states that the Stop Spammers Classic WordPress plugin is vulnerable to CSRF via a missing nonce in versions up to 2026.1, but offers no exploitation code, active‑use evidence, or patch information.

