Description
WordPress Plugin Contact Form 7 is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently submit arbitrary form data by omitting the '_wpcf7_captcha_challenge_captcha-719' parameter. WordPress Plugin Contact Form 7 version 3.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.7.2 or latest
References
Related Vulnerabilities
WordPress Plugin User Role by BestWebSoft Cross-Site Scripting (1.5.5)
WordPress Plugin Bulk Datetime Change Security Bypass (1.11)
WordPress 2.0.5 Cross-Site Scripting Vulnerability (0.6.2 - 2.0.5)
WordPress 4.2.x Arbitrary File Deletion Vulnerability (4.2 - 4.2.20)
WordPress Plugin Woo Email Control Cross-Site Scripting (1.01)