Description
WordPress Plugin Contact Form 7 is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently predict next values of the content of CAPTCHA. WordPress Plugin Contact Form 7 version 4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.1 or latest
References
Related Vulnerabilities
Better Search Replace Multiple Unspecified Vulnerabilities (1.0.3)
GN Publisher: Google News Compatible RSS Feeds Cross-Site Scripting (1.5.5)
MySQL CVE-2012-3173 Vulnerability (CVE-2012-3173)
Pike Firewall Information Disclosure (1.4)
WordPress 4.4.x Cross-Domain Flash Injection Vulnerability (4.4 - 4.4.13)