The Very Simple Contact Form WordPress plugin before 11.6...
High severity
Unreviewed
Published
Jun 21, 2022
to the GitHub Advisory Database
•
Updated Jul 24, 2023
Description
Published by the National Vulnerability Database
Jun 20, 2022
Published to the GitHub Advisory Database
Jun 21, 2022
Last updated
Jul 24, 2023
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots.
References