What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9.
Explanation of Vulnerability in Simple Terms
Captcha Code through version 2.9 contains a weakness in its CAPTCHA validation mechanism that allows attackers to bypass the CAPTCHA protection without user interaction. The vulnerability requires only network access and no authentication. This could enable automated attacks such as spam submission, account enumeration, or brute-force login attempts against sites using this plugin.
What an attacker can do
Bypass CAPTCHA validation to submit forms or perform automated attacks without solving the challenge.
Potential impact on your site
Spam, automated form submissions, and brute-force attacks may succeed against your site's protected forms.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities