CVE-2023-48745 MEDIUM

CVE-2023-48745: WordPress Captcha Code plugin <= 2.9 - Captcha Bypass vulnerability

Vendor Webfactory Ltd
Product Captcha Code
Weakness CWE-307 · Brute force
Published June 4, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9.

Explanation of Vulnerability in Simple Terms

02Summary

Captcha Code through version 2.9 contains a weakness in its CAPTCHA validation mechanism that allows attackers to bypass the CAPTCHA protection without user interaction. The vulnerability requires only network access and no authentication. This could enable automated attacks such as spam submission, account enumeration, or brute-force login attempts against sites using this plugin.

What an attacker can do

03Attacker Capabilities

Bypass CAPTCHA validation to submit forms or perform automated attacks without solving the challenge.

Potential impact on your site

04Site Impact

Spam, automated form submissions, and brute-force attacks may succeed against your site's protected forms.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 4, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE