Unauthenticated CAPTCHA Bypass in Joomla SP Page Builder Pro by JoomShaper
CVE-2026-79701
6.9MEDIUM
What is CVE-2026-79701?
An unauthenticated CAPTCHA bypass vulnerability exists within the SP Page Builder Pro extensions on joomshaper.com. In the ajax_contact, optin_form, and form_builder addons, the CAPTCHA validation mechanism fails to properly check the expected context. This occurs because the onCheckAnswer event's outcome is overridden by a simple test for a non-empty string when the request's view_type parameter equals 'module'. As a result, any arbitrary token can be submitted with view_type=module, effectively bypassing CAPTCHA verification. This affects all instances of these addons placed within a SP Page Builder module, regardless of the CAPTCHA type configured for the site.
Affected Version(s)
SP Page Builder (Pro) extension for Joomla 3.2.6 - 6.9.0
