CVE-2023-0085

MEDIUM

Metform Elementor Contact Form Builder <3.2.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha restrictions and for attackers to utilize bots to submit forms.

Scores

CVSS v3 5.3
EPSS 0.0069
EPSS Percentile 47.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-693
Status published
Products (2)
roxnor/MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor < 3.2.1
wpmet/metform_elementor_contact_form_builder < 3.2.1
Published Mar 02, 2023
Tracked Since Feb 18, 2026