CVE Published: 02/03/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: Wordfence |
Vendor: xpeedstudio |
Product: Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress Status : PUBLISHED
CVE-2023-0085 Description
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha restrictions and for attackers to utilize bots to submit forms.
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N