Unauthenticated CAPTCHA Bypass in Joomla Extension by JoomShaper
CVE-2026-79700

6.9MEDIUM

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-79700?

A vulnerability exists in the SP Page Builder Pro Joomla extension developed by JoomShaper, specifically affecting versions 5.1.4 through 6.9.0. This flaw allows an unauthenticated attacker to bypass CAPTCHA challenges on opt-in forms. The vulnerability arises from the addon reading the CAPTCHA configuration, including the type, expected answers, and enabled status, directly from the request parameters instead of from the stored configuration. This makes verification susceptible to manipulation, potentially allowing attackers to submit arbitrary CAPTCHA responses with minimal effort.

Affected Version(s)

SP Page Builder (Pro) extension for Joomla 5.1.4 - 6.9.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.