Impact
The vulnerability allows unauthenticated users to bypass the captcha mechanism provided by the Element Pack Elementor Addons plugin in WordPress. This bypass is an authentication control flaw, classified as CWE‑290, and permits attackers to submit forms or perform actions that the plugin originally required captcha confirmation for. The immediate consequence is the potential for indiscriminate spam or abuse, but no direct disclosure of sensitive data or code execution is indicated in the description.
Affected Systems
WordPress sites utilizing the bdthemes Element Pack Elementor Addons plugin version 8.7.13 or earlier are affected. The data does not reference any other vendors or products, so the impact is confined to this specific plugin on those versions.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the medium severity range. No EPSS score is publicly available, and it is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is a web‑based form submission that does not require prior user authentication, making exploitation straightforward and potentially viable through automated scripts. These conclusions are inferred from the description of the captcha bypass and the common exploitation methods for such vulnerabilities.
OpenCVE Enrichment