CVE-2008-7216 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 5.8% (pctl 93)
Patch early
A public exploit exists.
Description
Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the generated clip.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
| EPSS | 5.85% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-09-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| wordpress | peter\'s math anti-spam for wordpress |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin Peter's Math Anti-Spam 0.1.6 - Audio CAPTCHA Security Bypass | 2008-01-15 |
References
- http://docs.google.com/View?docid=df36cd52_19xzmkwqcg
- http://www.securityfocus.com/archive/1/486331/100/200/threaded
- http://www.securityfocus.com/bid/27287
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39688
- http://docs.google.com/View?docid=df36cd52_19xzmkwqcg
- http://www.securityfocus.com/archive/1/486331/100/200/threaded
- http://www.securityfocus.com/bid/27287
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39688
→ the Explorer · watch your stack · NVD