PT-2022-14124 · WordPress · Very Simple Contact Form
Sebastian Cruz Cardona
·
Published
2022-06-20
·
Updated
2023-07-24
·
CVE-2022-1801
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Very Simple Contact Form WordPress plugin versions prior to 11.6
Description
The issue allows bots to bypass the captcha check by exposing the solution in the rendered contact form as hidden input fields and plain text, making the page a target for spam bots.
Recommendations
For versions prior to 11.6, update to version 11.6 or later to resolve the issue.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Very Simple Contact Form