WS Form LITE <= 1.9.117 - CAPTCHA Bypass
2023-05-23 00:00
AnonymousStrategic Overview
StatusPatched in 1.9.118
Affected PluginWS Form LITE – Drag & Drop Contact Form Builder
Affected Version
<= 1.9.117CVSS5.3Medium
CVE
N/AVulnerability Overview
The WS Form LITE plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.9.117. This is due to the existence of a mechanism that allows the CAPTCHA to be bypassed if the client-side field is hidden (or omitted from the request). This makes it possible for unauthenticated attackers to bypass an intended protection mechanism for contact form submissions.
Technical Analysis
REMEDIATION: Update to version 1.9.118, or a newer patched version --- IDENTIFIER: CWE-602 (Client-Side Enforcement of Server-Side Security) The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C