Impact
The vulnerability is in the SP Page Builder Pro extension for Joomla, affecting versions 3.2.6 through 6.9.0. In the ajax_contact, optin_form and form_builder add‑ons, the result from the CAPTCHA plugin’s onCheckAnswer event is discarded and replaced with a test forplied view_type parameter equals "module". Submitting view_type=module with any token value therefore succeeds, allowing a user to send form data without passing the CAPTCHA. This flaw cannot be exploited for code execution.
Affected Systems
All Joomla sites that use the joomshaper.com SP Page Builder Pro extension at any version between 3.2.6 and 6.9.0 and have the ajax_contact, optin_form or form_builder add‑ons placed within an SP Page Builder module. The bypass occurs regardless of the CAPTCHA type configured for the site and the view_type parameter is not validated against the actual rendering context.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity flaw. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation at the time of analysis. The attack vector is a web application request; an attacker can craft an HTTP request with view_type=module and an arbitrary token to bypass the CAPTCHA. It is inferred that this flaw cannot be exploited for code execution. Because the bypass operates on any such form in module context, the impact can affect the entire site, enabling high‑volume spam or abuse.
OpenCVE Enrichment