VYPR
Medium severity5.4NVD Advisory· Published Dec 18, 2024· Updated Apr 15, 2026

CVE-2024-12554

CVE-2024-12554

Description

The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing nonce validation on the cas_register_post() function. This makes it possible for unauthenticated attackers to blacklist emails via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Peter’s Custom Anti-Spam plugin for WordPress has a CSRF flaw allowing unauthenticated attackers to trick admins into blacklisting emails.

The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 3.2.3. This is due to missing nonce validation on the cas_register_post() function, which processes requests to blacklist emails.

An unauthenticated attacker can exploit this by crafting a malicious request that, when triggered by an authenticated administrator (e.g., via a link), causes the plugin to blacklist specified email addresses. The attacker does not need any authentication but must trick a site admin into performing an action such as clicking a link.

Successful exploitation allows an attacker to blacklist arbitrary email addresses from the plugin’s settings, potentially blocking legitimate users from interacting with the site. This is a medium-severity CSRF vulnerability that could be used to disrupt site functionality.

The vulnerability has been patched in version 3.2.4, released on 2024-12-16, which adds proper nonce validation. Users are strongly advised to update to this latest version to mitigate the risk [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.