Description
WordPress Plugin Contact Form 7 is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently submit arbitrary form data by omitting the '_wpcf7_captcha_challenge_captcha-719' parameter. WordPress Plugin Contact Form 7 version 3.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.7.2 or latest
References
Related Vulnerabilities
Joomla! Core 3.x.x Cross-Site Request Forgery (3.7.0 - 3.9.18)
WordPress Plugin Simple visitor stat Cross-Site Scripting (1.0)
WebLogic CVE-2018-3250 Vulnerability (CVE-2018-3250)
Drupal Core 9.0.x Security Bypass (9.0.0 - 9.0.5)
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler Unspecified Vulnerability (5.1.2)