CVE-2025-24628 MEDIUM

CVE-2025-24628: WordPress reCaptcha by BestWebSoft Plugin <= 1.78 - Captcha Bypass vulnerability

Vendor Bestwebsoft
Product Google Captcha
Weakness CWE-290
Published January 27, 2025
Last update April 29, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78.

Explanation of Vulnerability in Simple Terms

02Summary

The Google Captcha plugin for WordPress contains an authentication bypass vulnerability in versions up to 1.78. An attacker can manipulate captcha validation to bypass security checks without providing a valid captcha response. This allows unauthorized form submissions and account actions to proceed unchecked. Site owners should update immediately to a patched version.

What an attacker can do

03Attacker Capabilities

Bypass captcha validation to submit forms or perform actions without solving the captcha challenge.

Potential impact on your site

04Site Impact

Spam, unauthorized form submissions, and automated attacks can bypass your captcha protection on all affected forms.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

January 27, 2025 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE