The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha restrictions and for attackers to utilize bots to submit forms.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Metform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection Bypass | |
| Weaknesses | CWE-693 | |
| References |
|
Mon, 13 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-03-02T16:01:14.196Z
Updated: 2026-04-08T16:58:37.427Z
Reserved: 2023-01-05T14:15:05.476Z
Link: CVE-2023-0085
Updated: 2024-08-02T05:02:42.994Z
Status : Modified
Published: 2023-03-02T17:15:09.957
Modified: 2026-04-08T18:17:40.800
Link: CVE-2023-0085
No data.