What the vulnerability does
01Description
Missing Authorization vulnerability in Bill Minozzi reCAPTCHA for all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects reCAPTCHA for all: from n/a through 1.22.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Bill Minozzi reCAPTCHA for all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects reCAPTCHA for all: from n/a through 1.22.
Explanation of Vulnerability in Simple Terms
The reCAPTCHA for all plugin through version 1.22 lacks proper authorization checks on certain functions. A logged-in user with low privileges can modify settings or data they should not have access to. The vulnerability does not expose sensitive information or cause service disruption, but allows unauthorized changes to plugin configuration.
What an attacker can do
Modify plugin settings or data without proper authorization.
Potential impact on your site
Unauthorized users may alter reCAPTCHA settings, potentially disabling protections or changing site behavior.
Conditions required to exploit
Attacker must be logged in with a low-privilege user account.
Key dates
External resources
Related vulnerabilities