What the vulnerability does
01Description
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from the 'data' array.
Explanation of Vulnerability in Simple Terms
02Summary
Getwid – Gutenberg Blocks versions 2.0.4 and earlier contain an integrity vulnerability that allows unauthenticated attackers to modify data over the network without user interaction. The vulnerability stems from insufficient input validation or access controls. Site administrators should update to a version newer than 2.0.4 to mitigate the risk.
What an attacker can do
03Attacker Capabilities
Modify site data without authentication or user interaction.
Potential impact on your site
04Site Impact
Attackers can alter plugin-managed content or settings without logging in.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user action required.
Key dates
06Disclosure timeline
February 5, 2024
CVE published
April 8, 2026
Record updated