CVE-2026-79700: Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0

Published Sep 14, 2026
·
Updated

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optinform addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification reduced to md5($captchaquestion) != $captchaanswer with both operands supplied by the attacker, so any value passed.

Affected Software

1 affected component
SP Page Builder Pro>=5.1.4<=6.9.0

Event History

Sep 14, 2026
CVE Published
via MITRE·10:59 AM
Data Sourced
via MITRE·10:59 AM
DescriptionWeakness

Frequently Asked Questions

1

Does exploiting this issue require a Joomla account or prior authentication?

No. The affected optin_form addon can be bypassed by an unauthenticated attacker.

2

What does an attacker need to control to bypass CAPTCHA verification?

The attacker must be able to supply CAPTCHA-related request values, including the CAPTCHA type, expected answer, and enabled flag. Because the verification compared attacker-supplied operands, the attacker could make the check pass with arbitrary values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203