Calculated Fields Form <= 5.2.63 - Denial of Service
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.6%
probabilidad de explotación
0.6%top 57% de las CVE
explotación observada
noninguna fuente lo reporta
The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in slowing server resources if the server does not mitigate Denial of Service attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Productos afectados
codepeople · Calculated Fields FormReferencias
https://plugins.trac.wordpress.org/browser/calculated-fields-form/trunk/captcha/captcha.php#L74https://plugins.trac.wordpress.org/browser/calculated-fields-form/trunk/captcha/captcha.php#L75https://plugins.trac.wordpress.org/changeset/3207826/https://www.wordfence.com/threat-intel/vulnerabilities/id/1eade2ed-9a75-4857-a2c5-a21e016e7029?source=cve