Unauthenticated CAPTCHA Bypass in Joomla SP Page Builder Pro by JoomShaper
CVE-2026-79701

6.9MEDIUM

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-79701?

An unauthenticated CAPTCHA bypass vulnerability exists within the SP Page Builder Pro extensions on joomshaper.com. In the ajax_contact, optin_form, and form_builder addons, the CAPTCHA validation mechanism fails to properly check the expected context. This occurs because the onCheckAnswer event's outcome is overridden by a simple test for a non-empty string when the request's view_type parameter equals 'module'. As a result, any arbitrary token can be submitted with view_type=module, effectively bypassing CAPTCHA verification. This affects all instances of these addons placed within a SP Page Builder module, regardless of the CAPTCHA type configured for the site.

Affected Version(s)

SP Page Builder (Pro) extension for Joomla 3.2.6 - 6.9.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.