CVE-2014-2265: Medium severity Rocklobster Contact Form 7 Wordpress vulnerability
Published Mar 14, 2014
·Updated
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the wpcf7captchachallengecaptcha-719 parameter.
Affected Software
8 affected components
Rocklobster Contact Form 7 Wordpress<=3.7.1
Rocklobster Contact Form 7 Wordpress=3.6
Rocklobster Contact Form 7 Wordpress=3.7
WordPress WordPress
All of the following
Any of the following
Rocklobster Contact Form 7 Wordpress<=3.7.1
Rocklobster Contact Form 7 Wordpress=3.6
Rocklobster Contact Form 7 Wordpress=3.7
WordPress WordPress
Remediation
Patch Available
Event History
Mar 14, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2265?
CVE-2014-2265 has a medium severity rating, highlighting a potential risk to data integrity.
2
How do I fix CVE-2014-2265?
To fix CVE-2014-2265, update Rock Lobster Contact Form 7 to version 3.7.2 or later to restore CAPTCHA functionality.
3
What does CVE-2014-2265 exploit?
CVE-2014-2265 exploits the ability to bypass CAPTCHA protection in older versions of Rock Lobster Contact Form 7.
4
Who is affected by CVE-2014-2265?
Users of Rock Lobster Contact Form 7 versions prior to 3.7.2 are affected by CVE-2014-2265.
5
Can CVE-2014-2265 lead to spam submissions?
Yes, CVE-2014-2265 can allow attackers to submit arbitrary form data, leading to potential spam submissions.