Peter's Math Anti-Spam Spinoff < 1.0.0 - CAPTCHA Bypass

2008-01-15 00:00
Jose Palazon

Strategic Overview

Status
Patched in 1.0.0
Affected PluginPeter's Math Anti-Spam
Affected Version<= 0.1.6
CVSS7.5High
CVECVE-2008-7216
View all Peter's Math Anti-Spam vulnerabilities

Vulnerability Overview

The Peter's Math Anti-Spam Spinoff plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to 1.0.0. This is due to the plugin generating audio CAPTCHA clips by concatenating static audio files without any additional distortion. This makes it possible for unauthenticated attackers to bypass the Captcha Verification by reading certain bytes from the generated clip.

Technical Analysis

REMEDIATION: Update to version 1.0.0, or a newer patched version --- IDENTIFIER: CWE-804 (Guessable CAPTCHA) The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C