Description
Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification reduced to md5($captcha_question) != $captcha_answer with both operands supplied by the attacker, so any value passed.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: CAPTCHA Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in versions 5.1.4 to 6 Pro extension for Joomla. The optin_form addon incorrectly reads the CAPTCHA type, expected answer, and the enabled flag from the HTTP request instead an attacker can supply arbitrary values for these parameters. The verification step collapses to a comparison that the attacker can trivially satisfy, effectively allowing CAPTCHA validation to be bypassed. This can enable automated spam, form abuse, and other unauthorized actions that normally require user interaction with a CAPTCHA.

Affected Systems

All installations of the SP Page Builder (Pro) extension for Joomla provided by joomshaper.com that are using any version from 5.1.4 up to 6.9.0 are affected. The vulnerability is tied to the optin_form addon bundled with the extension.

Risk and Exploitability

The CVSS base score of 6.9 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The issue is exploitable without authentication by manipulating request parameters directed at the optin_form addon. Because the attacker can provide arbitrary CAPTCHA answers, the exploit requires only the ability to send crafted HTTP requests to the extension’s endpoints, which is typically obtainable from any web host that runs Joomla with the vulnerable extension. In practice, automated scripts or bots could exploit the flaw to flood forms or bypass security controls that rely on CAPTCHA verification.

Generated by OpenCVE AI on September 15, 2026 at 14:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SP Page Builder Pro extension to the latest version that includes the fix.
  • If an upgrade is not immediately possible, disable the optin_form addon or remove the CAPTCHA functionality from the forms that use it.
  • Implement input validation or server‑side rules that enforce CAPTCHA settings from stored configuration rather than request data, and consider blocking or rate‑limiting automated requests to the problematic endpoints.

Generated by OpenCVE AI on September 15, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification reduced to md5($captcha_question) != $captcha_answer with both operands supplied by the attacker, so any value passed.
Title Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0
Weaknesses CWE-807
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:45:35.310Z

Reserved: 2026-08-25T12:25:17.262Z

Link: CVE-2026-79700

cve-icon Vulnrichment

Updated: 2026-09-14T14:26:33.131Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:04.570

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-79700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision