PT-2026-85502 · Grav · Grav Form

·

CVE-2026-85602

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grav Form plugin versions 8.0.6 through 9.1.19
Description The plugin determines which reCAPTCHA version to use for validation based only on the response field key present in the submitted payload. On sites configured for reCAPTCHA v3, an anonymous attacker can submit a v3 token using the v2 field name g-recaptcha-response instead of token. This forces the validation to use the v2 logic, which does not verify the expected action or apply the score threshold, resulting in a complete bypass of the bot protection.
Recommendations Update Grav Form plugin to version 9.1.20.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85602

Affected Products

Grav Form