Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 10 vulnerability records associated with Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection, published between 2021 and 2025.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

10Total records
3Critical
1High
6Medium
0Low
0Informational
10Patched records
0Currently marked unpatched
2021-08-06First disclosure
2025-08-27Latest disclosure
8 of 10CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202144 records
202233 records
202311 records
202411 records
202511 records

Severity Breakdown

SeverityRecordsShare
Critical330%
High110%
Medium660%

Vulnerability-Type Breakdown

SQL Injection

4 records40%

First: 2021. Latest: 2022.

Cross-Site Scripting

3 records30%

First: 2021. Latest: 2023.

Missing Authorization

3 records30%

First: 2022. Latest: 2025.

Patch Status

Patched
10
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 11.59
  • 10.24
  • 7.32
  • 7.24
  • 6.930
  • 6.90
  • 6.62
  • 6.67
  • 6.60

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-11.58Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 - Insufficient Authorization to Unauthenticated Blocklist BypassAugust 27, 202511.59Medium
*-10.23Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.23 - Missing Authorization to Information ExpsoureMay 29, 202410.24Medium
*-7.31StopBadBots <= 7.31 - Authenticated (Administrator+) Stored Cross-Site ScriptingMay 9, 20237.32Medium
*-7.23StopBadBots <= 7.23 - Missing Authorization to Arbitrary Plugin InstallationNovember 18, 20227.24Medium
[*, 6.930)WP Block and Stop Bad Bots <= 6.92 - SQL InjectionMarch 16, 20226.930Critical
[*, 6.88)WP Block and Stop Bad Bots <= 6.88 - SQL InjectionMarch 8, 20226.90Critical
[*, 6.67)WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.67 - Unauthenticated SQL InjectionNovember 15, 20216.67Critical
*-6.61Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 6.61 - Reflected Cross-Site ScriptingAugust 25, 20216.62Medium
[*, 6.67)Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection < 6.6.7 - Reflected Cross-Site ScriptingAugust 25, 20216.67Medium
[*, 6.60)WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.60 - Authenticated SQL InjectionAugust 6, 20216.60High

Selected source records

Latest Records

MediumCVE-2025-9376

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 - Insufficient Authorization to Unauthenticated Blocklist Bypass

Published: August 27, 2025

Affected versions
*-11.58
Patched versions
11.59
Original Wordfence record
MediumCVE-2024-4355

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.23 - Missing Authorization to Information Expsoure

Published: May 29, 2024

Affected versions
*-10.23
Patched versions
10.24
Original Wordfence record
MediumCVE-2023-32496

StopBadBots <= 7.31 - Authenticated (Administrator+) Stored Cross-Site Scripting

Published: May 9, 2023

Affected versions
*-7.31
Patched versions
7.32
Original Wordfence record
MediumCVE-2022-3883

StopBadBots <= 7.23 - Missing Authorization to Arbitrary Plugin Installation

Published: November 18, 2022

Affected versions
*-7.23
Patched versions
7.24
Original Wordfence record
CriticalCVE-2022-0949

WP Block and Stop Bad Bots <= 6.92 - SQL Injection

Published: March 16, 2022

Affected versions
[*, 6.930)
Patched versions
6.930
Original Wordfence record
CriticalCVE-2021-25070

WP Block and Stop Bad Bots <= 6.88 - SQL Injection

Published: March 8, 2022

Affected versions
[*, 6.88)
Patched versions
6.90
Original Wordfence record
CriticalCVE-2021-24863

WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.67 - Unauthenticated SQL Injection

Published: November 15, 2021

Affected versions
[*, 6.67)
Patched versions
6.67
Original Wordfence record
Medium

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection < 6.6.7 - Reflected Cross-Site Scripting

Published: August 25, 2021

Affected versions
[*, 6.67)
Patched versions
6.67
Original Wordfence record

Highest-Severity Records

CriticalCVE-2021-25070

WP Block and Stop Bad Bots <= 6.88 - SQL Injection

Published: March 8, 2022

Affected versions
[*, 6.88)
Patched versions
6.90
Original Wordfence record
CriticalCVE-2022-0949

WP Block and Stop Bad Bots <= 6.92 - SQL Injection

Published: March 16, 2022

Affected versions
[*, 6.930)
Patched versions
6.930
Original Wordfence record
CriticalCVE-2021-24863

WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.67 - Unauthenticated SQL Injection

Published: November 15, 2021

Affected versions
[*, 6.67)
Patched versions
6.67
Original Wordfence record
HighCVE-2021-24727

WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots < 6.60 - Authenticated SQL Injection

Published: August 6, 2021

Affected versions
[*, 6.60)
Patched versions
6.60
Original Wordfence record
MediumCVE-2022-3883

StopBadBots <= 7.23 - Missing Authorization to Arbitrary Plugin Installation

Published: November 18, 2022

Affected versions
*-7.23
Patched versions
7.24
Original Wordfence record
MediumCVE-2025-9376

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 11.58 - Insufficient Authorization to Unauthenticated Blocklist Bypass

Published: August 27, 2025

Affected versions
*-11.58
Patched versions
11.59
Original Wordfence record
Medium

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection < 6.6.7 - Reflected Cross-Site Scripting

Published: August 25, 2021

Affected versions
[*, 6.67)
Patched versions
6.67
Original Wordfence record
Medium

Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 6.61 - Reflected Cross-Site Scripting

Published: August 25, 2021

Affected versions
*-6.61
Patched versions
6.62
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory