What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0.0.
Explanation of Vulnerability in Simple Terms
WP Captcha through version 2.0.0 contains a weak authentication mechanism that allows attackers to bypass CAPTCHA verification without user interaction. An attacker on the network can read sensitive information or bypass security controls by exploiting insufficient rate limiting or token validation. This affects any WordPress site using the plugin for form protection.
What an attacker can do
Bypass CAPTCHA verification and read sensitive information without solving the challenge.
Potential impact on your site
Forms protected by this plugin can be submitted without solving the CAPTCHA, enabling spam, automated attacks, and unauthorized data access.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities