The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/5231ac18-ea9a-4bb9-af9f-e3d95a3b54f1 | Exploit Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-09-16 02:15
Updated : 2022-09-20 10:44
NVD link : CVE-2022-2913
Mitre link : CVE-2022-2913
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
login_no_captcha_recaptcha_project
- login_no_captcha_recaptcha