CVE-2023-44235 MEDIUM

CVE-2023-44235: WordPress WP Captcha plugin <= 2.0.0 - Captcha Bypass vulnerability

Vendor Devnath Verma
Product WP Captcha
Weakness CWE-307 · Brute force
Published June 4, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0.0.

Explanation of Vulnerability in Simple Terms

02Summary

WP Captcha through version 2.0.0 contains a weak authentication mechanism that allows attackers to bypass CAPTCHA verification without user interaction. An attacker on the network can read sensitive information or bypass security controls by exploiting insufficient rate limiting or token validation. This affects any WordPress site using the plugin for form protection.

What an attacker can do

03Attacker Capabilities

Bypass CAPTCHA verification and read sensitive information without solving the challenge.

Potential impact on your site

04Site Impact

Forms protected by this plugin can be submitted without solving the CAPTCHA, enabling spam, automated attacks, and unauthorized data access.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 4, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE