VYPR

Blackhole For Bad Bots

by WordPress

CVEs (2)

  • CVE-2022-1165CriApr 4, 2022
    risk 0.52cvss 9.1epss 0.02

    The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as…

  • CVE-2026-4329HigMar 26, 2026
    risk 0.47cvss 7.2epss 0.00

    The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() when…