Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
| Software | From | Fixed in |
|---|---|---|
| rocklobster / contact_form_7 | - | 3.7.1.x |
| rocklobster / contact_form_7 | 3.6 | 3.6.x |
| rocklobster / contact_form_7 | 3.7 | 3.7.x |