CVE-2024-30540 MEDIUM

CVE-2024-30540: WordPress VS Contact Form plugin <= 14.7 - Sum Captcha Bypass vulnerability

Vendor Guido
Product VS Contact Form
Weakness CWE-804
Published May 17, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.

Explanation of Vulnerability in Simple Terms

02Summary

VS Contact Form versions up to 14.7 contain an information disclosure vulnerability. An attacker on the network can read sensitive data from the application without authentication or user interaction. The vulnerability has a CVSS score of 5.3, indicating moderate risk to confidentiality. Administrators should update to a version newer than 14.7 when available.

What an attacker can do

03Attacker Capabilities

Read sensitive information from the contact form application without authentication.

Potential impact on your site

04Site Impact

Sensitive data may be exposed to unauthenticated attackers, potentially including form submissions or configuration details.

Conditions required to exploit

05Prerequisites

Network access to the affected application; no authentication or user interaction required.

Key dates

06Disclosure timeline

May 17, 2024 CVE published
April 28, 2026 Record updated