CformsII <= 14.10.1 - CAPTCHA Bypass

2010-12-15 00:00
TheLightCosine

Strategic Overview

Status
Patched in 14.11
Affected PlugincformsII
Affected Version<= 14.10.1
CVSS5.3Medium
CVEN/A
View all cformsII vulnerabilities

Vulnerability Overview

The CformsII plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.10.1. This is due to the codes not being one-time use and improper verification of user-supplied data. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.

Technical Analysis

REMEDIATION: Update to version 14.11, or a newer patched version --- IDENTIFIER: CWE-804 (Guessable CAPTCHA) The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C