CVE-2024-12601

MEDIUM

Calculated Fields Form <= 5.2.63 - Unauthenticated Denial of Service via CAPTCHA Image Dimensions

Title source: llm
STIX 2.1

Description

The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in slowing server resources if the server does not mitigate Denial of Service attacks.

Scores

CVSS v3 5.3
EPSS 0.0054
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
codepeople/Calculated Fields Form < 5.2.63
codepeople/calculated_fields_form < 5.2.64
Published Dec 17, 2024
Tracked Since Feb 18, 2026