The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/5231ac18-ea9a-4bb9-af9f-e3d95a3b54f1 | Exploit Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2022-09-16 09:15
Updated : 2022-09-20 17:44
NVD link : CVE-2022-2913
Mitre link : CVE-2022-2913
CVE.ORG link : CVE-2022-2913
JSON object : View
Products Affected
login_no_captcha_recaptcha_project
- login_no_captcha_recaptcha
CWE
CWE-639
Authorization Bypass Through User-Controlled Key