Peter's Math Anti-Spam Spinoff < 1.0.0 - CAPTCHA Bypass
2008-01-15 00:00
Jose PalazonStrategic Overview
StatusPatched in 1.0.0
Affected PluginPeter's Math Anti-Spam
Affected Version
<= 0.1.6CVSS7.5High
CVE
CVE-2008-7216Vulnerability Overview
The Peter's Math Anti-Spam Spinoff plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to 1.0.0. This is due to the plugin generating audio CAPTCHA clips by concatenating static audio files without any additional distortion. This makes it possible for unauthenticated attackers to bypass the Captcha Verification by reading certain bytes from the generated clip.
Technical Analysis
REMEDIATION: Update to version 1.0.0, or a newer patched version --- IDENTIFIER: CWE-804 (Guessable CAPTCHA) The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C