What the vulnerability does
01Description
The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in slowing server resources if the server does not mitigate Denial of Service attacks.
Explanation of Vulnerability in Simple Terms
02Summary
Calculated Fields Form versions up to 5.2.63 do not properly limit resource consumption, allowing an attacker to send repeated requests that exhaust server resources and cause the site to become slow or unresponsive. No authentication is required. The vulnerability affects availability only; attackers cannot read or modify data.
What an attacker can do
03Attacker Capabilities
Make repeated requests to exhaust server resources and degrade site performance.
Potential impact on your site
04Site Impact
Your site may become slow or temporarily unavailable if targeted with resource-exhaustion requests.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 17, 2024
CVE published
April 8, 2026
Record updated