// For flags

CVE-2014-2265

Contact Form 7 < 3.7.2 - CAPTCHA Bypass

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.

Rock Lobster Contact Form 7 anterior a 3.7.2 permite a los atacantes remotos omitir el mecanismo de protección CAPTCHA y enviar datos de formularios arbitrarios omitiendo el parámetro _wpcf7_captcha_challenge_captcha-719.

*Credits: Hannah Sharp
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-02-26 CVE Published
  • 2014-03-04 CVE Reserved
  • 2024-01-25 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
  • CWE-693: Protection Mechanism Failure
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rocklobster
Search vendor "Rocklobster"
Contact Form 7
Search vendor "Rocklobster" for product "Contact Form 7"
<= 3.7.1
Search vendor "Rocklobster" for product "Contact Form 7" and version " <= 3.7.1"
wordpress
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
--
Safe
Rocklobster
Search vendor "Rocklobster"
Contact Form 7
Search vendor "Rocklobster" for product "Contact Form 7"
3.6
Search vendor "Rocklobster" for product "Contact Form 7" and version "3.6"
wordpress
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
--
Safe
Rocklobster
Search vendor "Rocklobster"
Contact Form 7
Search vendor "Rocklobster" for product "Contact Form 7"
3.7
Search vendor "Rocklobster" for product "Contact Form 7" and version "3.7"
wordpress
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
--
Safe