CVE-2023-48318: WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerability
Published Jun 4, 2024
·Updated
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.
Affected Software
3 affected components
CodePeople Contact Form Email Wordpress<1.3.42
CodePeople Contact Form Email<=1.3.41
WordPress Contact Form Email<=1.3.41
Remediation
Information
Update to 1.3.42 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·10:26 AM
Data Sourced
via MITRE·10:26 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 24, 57160
Event
via NVD·05:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-48318?
CVE-2023-48318 is classified as a medium severity vulnerability due to its improper restriction of excessive authentication attempts.
2
How do I fix CVE-2023-48318?
To fix CVE-2023-48318, update the CodePeople Contact Form Email plugin to version 1.3.42 or later.
3
What versions are affected by CVE-2023-48318?
CVE-2023-48318 affects CodePeople Contact Form Email versions up to and including 1.3.41.
4
What does the CVE-2023-48318 vulnerability allow an attacker to do?
CVE-2023-48318 allows attackers to bypass authentication restrictions, which could lead to unauthorized access.
5
Is CVE-2023-48318 specific to a certain platform?
Yes, CVE-2023-48318 specifically affects the CodePeople Contact Form Email plugin on WordPress.