PT-2024-12998 · WordPress · Very Simple Contact Form+1
Qilin_99
·
Published
2024-12-13
·
Updated
2024-12-17
·
CVE-2023-41862
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Very Simple Contact Form plugin versions prior to 13.9
VS Contact Form versions prior to 14.0
Description
The issue affects the Very Simple Contact Form plugin for WordPress, allowing a CAPTCHA bypass due to a Weak Authentication vulnerability. This enables Authentication Abuse. Users are urged to update to the latest version to mitigate risks.
Recommendations
For Very Simple Contact Form plugin versions prior to 13.9, update to the latest version to secure your site.
For VS Contact Form versions prior to 14.0, update to the latest version to protect against Authentication Abuse.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form
Very Simple Contact Form