CVE-2023-45009 MEDIUM

CVE-2023-45009: WordPress Captcha for Contact Form 7 plugin <= 1.11.3 - Capcha Bypass vulnerability

Vendor Forge12 Interactive Gmbh
Product Captcha/Honeypot for Contact Form 7
Weakness CWE-307 · Brute force
Published June 4, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affects Captcha/Honeypot for Contact Form 7: from n/a through 1.11.3.

Explanation of Vulnerability in Simple Terms

02Summary

The Captcha/Honeypot for Contact Form 7 plugin contains a weakness in its rate-limiting or brute-force protection mechanism (CWE-307). An attacker can send repeated requests to bypass CAPTCHA validation without authentication. This allows automated attacks against contact forms and other protected endpoints. Update to a version newer than 1.11.3.

What an attacker can do

03Attacker Capabilities

Bypass CAPTCHA protection and submit forms repeatedly without solving the challenge.

Potential impact on your site

04Site Impact

Contact forms and other protected endpoints become vulnerable to spam, automated attacks, and form submission abuse.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 4, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE