Strategic Overview
- Status
- Patched in 3.7.2
- Affected Plugin
- Contact Form 7
- Affected Version
< 3.7.2- CVSS
- 5.3Medium
- Weakness type
- CWE-693 · Protection Mechanism Failure
- CVE
CVE-2014-2265
At a glance
CVE-2014-2265 is a medium-severity Protection Mechanism Failure vulnerability in the Contact Form 7 WordPress plugin, affecting versions < 3.7.2. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 3.7.2; sites on affected versions should update now. Disclosed February 2014, reported by Hannah Sharp.
Vulnerability Overview
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-693: Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Remediation
Update to version 3.7.2, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Contact Form 7 3.7.2 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Contact Form 7
- 9.8Contact Form 7 <= 3.5.2 Arbitrary File Upload
- 8.1CVE-2020-35489: Contact Form 7 <= 5.3.1 Arbitrary File Upload
CVE-2020-35489 - 6.6CVE-2023-6449: Contact Form 7 <= 5.8.3 Arbitrary File Upload
CVE-2023-6449 - 6.3CVE-2018-20979: Contact Form 7 <= 5.0.3 Authorization Bypass
CVE-2018-20979 - 6.1CVE-2024-4704: Contact Form 7 <= 5.9.4 Open Redirect
CVE-2024-4704 - 6.1CVE-2024-2242: Contact Form 7 <= 5.9 Reflected Cross-Site Scripting
CVE-2024-2242 - 5.3CVE-2025-3247: Contact Form 7 <= 6.0.5 Order Replay Vulnerability
CVE-2025-3247
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C