Junglewise Threat Intelligence

CVE-2026-79701: JoomShaper SP Page Builder Pro CAPTCHA bypass in addons

CVE-2026-79701 · Severity: info · CVSS 7.5 · Published 2026-09-14

Technologies: JoomShaper SP Page Builder Pro. Vendors: JoomShaper.

Executive brief

SP Page Builder Pro is a popular drag-and-drop page composer extension for Joomla that includes form-building capabilities with CAPTCHA protection. A vulnerability in three addons (Contact, Opt-in, and Form Builder) allows attackers to bypass CAPTCHA verification entirely by simply submitting a module context parameter, making it possible to submit unauthorized forms without proving human identity—a serious risk for contact forms, newsletter signups, and other protected submissions.

Technical details

This vulnerability affects the ajax_contact, optin_form, and form_builder addons in SP Page Builder Pro versions 3.2.6 through 6.9.0. The root cause is improper handling of the CAPTCHA verification response when the view_type parameter is set to "module": the addon discards the CAPTCHA plugin's onCheckAnswer result and replaces it with a simple check for a non-empty token string, effectively bypassing all CAPTCHA validation. The attack requires no authentication and can be exploited remotely by any user able to access the form; the view_type parameter is never validated against the actual rendering context. This affects all instances of these addons placed within SP Page Builder modules regardless of the CAPTCHA type configured site-wide.

Affected products

  • JoomShaper SP Page Builder Pro 3.2.6 - 6.9.0

Timeline

  • 2026-09-14: disclosed

References

Related threats