Unauthenticated CAPTCHA Bypass in Joomla Extension by JoomShaper
CVE-2026-79700
6.9MEDIUM
What is CVE-2026-79700?
A vulnerability exists in the SP Page Builder Pro Joomla extension developed by JoomShaper, specifically affecting versions 5.1.4 through 6.9.0. This flaw allows an unauthenticated attacker to bypass CAPTCHA challenges on opt-in forms. The vulnerability arises from the addon reading the CAPTCHA configuration, including the type, expected answers, and enabled status, directly from the request parameters instead of from the stored configuration. This makes verification susceptible to manipulation, potentially allowing attackers to submit arbitrary CAPTCHA responses with minimal effort.
Affected Version(s)
SP Page Builder (Pro) extension for Joomla 5.1.4 - 6.9.0
