Description
Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's onCheckAnswer event was discarded and replaced with a test for a non-empty string whenever the request-supplied view_type parameter equalled module. Submitting view_type=module together with any arbitrary token value therefore passed verification. This affected every instance of these addons placed inside an SP Page Builder module, irrespective of the CAPTCHA type configured for the site, and the view_type parameter was never validated against the context in which the form was actually rendered.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: CAPTCHA bypass enabling unauthorized form submissions
Action: Update
AI Analysis

Impact

The vulnerability is in the SP Page Builder Pro extension for Joomla, affecting versions 3.2.6 through 6.9.0. In the ajax_contact, optin_form and form_builder add‑ons, the result from the CAPTCHA plugin’s onCheckAnswer event is discarded and replaced with a test forplied view_type parameter equals "module". Submitting view_type=module with any token value therefore succeeds, allowing a user to send form data without passing the CAPTCHA. This flaw cannot be exploited for code execution.

Affected Systems

All Joomla sites that use the joomshaper.com SP Page Builder Pro extension at any version between 3.2.6 and 6.9.0 and have the ajax_contact, optin_form or form_builder add‑ons placed within an SP Page Builder module. The bypass occurs regardless of the CAPTCHA type configured for the site and the view_type parameter is not validated against the actual rendering context.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity flaw. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation at the time of analysis. The attack vector is a web application request; an attacker can craft an HTTP request with view_type=module and an arbitrary token to bypass the CAPTCHA. It is inferred that this flaw cannot be exploited for code execution. Because the bypass operates on any such form in module context, the impact can affect the entire site, enabling high‑volume spam or abuse.

Generated by OpenCVE AI on September 15, 2026 at 14:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SP Page Builder Pro to a patched version that restores proper CAPTCHA verification for module contexts.
  • If an update is not immediately possible, temporarily disable the CAPTCHA plugin for forms rendered within SP Page Builder modules or move those forms to a non‑module context.
  • Monitor form activity for suspicious submissions and consider rate limiting or additional spam‑control measures while the vulnerability remains present.

Generated by OpenCVE AI on September 15, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's onCheckAnswer event was discarded and replaced with a test for a non-empty string whenever the request-supplied view_type parameter equalled module. Submitting view_type=module together with any arbitrary token value therefore passed verification. This affected every instance of these addons placed inside an SP Page Builder module, irrespective of the CAPTCHA type configured for the site, and the view_type parameter was never validated against the context in which the form was actually rendered.
Title Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0
Weaknesses CWE-807
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:49:11.567Z

Reserved: 2026-08-25T12:25:17.262Z

Link: CVE-2026-79701

cve-icon Vulnrichment

Updated: 2026-09-14T14:30:26.911Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T12:17:46.137

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-79701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision