What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78.
Explanation of Vulnerability in Simple Terms
The Google Captcha plugin for WordPress contains an authentication bypass vulnerability in versions up to 1.78. An attacker can manipulate captcha validation to bypass security checks without providing a valid captcha response. This allows unauthorized form submissions and account actions to proceed unchecked. Site owners should update immediately to a patched version.
What an attacker can do
Bypass captcha validation to submit forms or perform actions without solving the captcha challenge.
Potential impact on your site
Spam, unauthorized form submissions, and automated attacks can bypass your captcha protection on all affected forms.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities