Impact
The Invisible Anti‑Spam & CAPTCHA plugin fails to verify a user’s capabilities when processing its message deletion AJAX action. The plugin merely checks for the presence of a nonce, which is insufficient for authentication, allowing any logged‑in user—including subscribers—to permanently delete every form submission stored by the plugin. This flaw directly results in loss of data, compromising the integrity of form submissions collected on the site.
Affected Systems
Any WordPress site running the Invisible Anti‑Spam & CAPTCHA – reCAPTCHA Alternative for All Forms plugin prior to version 5.1.1 is vulnerable. The issue applies to all installations where the plugin is active and users can submit forms, regardless of the site’s theme or additional plugins.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability is considered moderate. The EPSS score of less than 1% indicates a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the deletion action can be exercised by any authenticated user, an attacker with a subscriber account could exploit the flaw by sending a crafted AJAX request to the plugin’s deletion endpoint, resulting in wholesale removal of stored form submissions.
OpenCVE Enrichment