The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it possible for unauthenticated attackers to unblock their IP after being locked out due to too many bad password attempts
History

Tue, 24 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Dec 2024 05:30:00 +0000

Type Values Removed Values Added
Description The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it possible for unauthenticated attackers to unblock their IP after being locked out due to too many bad password attempts
Title Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock
Weaknesses CWE-340
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-24T05:23:42.564Z

Updated: 2024-12-24T16:48:22.800Z

Reserved: 2024-12-02T16:32:30.112Z

Link: CVE-2024-12034

cve-icon Vulnrichment

Updated: 2024-12-24T16:48:18.514Z

cve-icon NVD

Status : Received

Published: 2024-12-24T06:15:32.553

Modified: 2024-12-24T06:15:32.553

Link: CVE-2024-12034

cve-icon Redhat

No data.