cleantalk
Vulnerabilities and Security Researches

Metform Elementor Contact Form Builder, CVE-2023-0085

CVE, Research URL

CVE-2023-0085

Published on
Mar 02, 2023
Research Description
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha restrictions and for attackers to utilize bots to submit forms.
Affected versions
Min -, max 3.2.2.
Status
vulnerable