WordPress Plugin Vulnerabilities

Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletion

Description

The plugin does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to permanently delete every form submission the plugin has stored.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
JunHee CHO
Submitter
JunHee CHO
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-15 (about 2 days ago)
Added
2026-09-15 (about 1 day ago)
Last Updated
2026-09-15 (about 1 day ago)

Other