Description
WordPress Plugin Contact Form 7 is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently submit arbitrary form data by omitting the '_wpcf7_captcha_challenge_captcha-719' parameter. WordPress Plugin Contact Form 7 version 3.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.7.2 or latest
References
Related Vulnerabilities
WordPress Plugin Redirection HTTP Referrer Header HTML Injection (2.2.9)
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.23)
Oracle JRE CVE-2019-2958 Vulnerability (CVE-2019-2958)
Drupal Core 5.x Multiple Vulnerabilities (5.0 - 5.12)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5317)