VulnerabilityModified
CVE-2014-2265
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
MEDIUM 5.0EPSS 3.06%
Does this matter?
Lower severity and a low EPSS score (3.06%). Track it; it rarely justifies an emergency change on its own.
Description
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.06% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- rocklobster/contact form 7
- Source
- cve@mitre.org
References
- http://contactform7.com/2014/02/26/contact-form-7-372/Patch, Vendor Advisory
- http://web.archive.org/web/20140727133642/http://www.hedgehogsecurity.co.uk/2014/02/26/contactform7-vulnerability/
- http://wordpress.org/plugins/contact-form-7/changelog
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-contact-form-7-security-bypass-3-7-1/
- https://www.cvedetails.com/cve/CVE-2014-2265/
- http://contactform7.com/2014/02/26/contact-form-7-372/Patch, Vendor Advisory
- http://web.archive.org/web/20140727133642/http://www.hedgehogsecurity.co.uk/2014/02/26/contactform7-vulnerability/
- http://wordpress.org/plugins/contact-form-7/changelog
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-contact-form-7-security-bypass-3-7-1/
- https://www.cvedetails.com/cve/CVE-2014-2265/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.