Description
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Patch
AI Analysis

Impact

An unauthenticated bypass vulnerability exists in the hCaptcha for WP plugin versions 5.3.0 and earlier. The flaw permits an attacker to bypass authentication checks that the plugin normally enforces, enabling unauthorized interactions with the plugin’s protected features. This issue is classified as CWE-290, indicating an authentication bypass. Successful exploitation could compromise the confidentiality and integrity of the WordPress site and may serve as a foothold for subsequent attacks.

Affected Systems

The affected product is the hCaptcha for WP plugin by hCaptcha, with vulnerability present in versions up to and including 5.3.0. Site administrators using these versions are impacted; later versions are not affected.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability represents a moderate risk, and its EPSS score is currently unavailable, leaving exploitation frequency uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s form interfaces exposed on a WordPress site; an attacker can send crafted requests to the form endpoints to trigger the bypass. Because the flaw does not require authentication, attackers can perform the exploit without prior credentials, making it accessible to anyone who can reach the affected site.

Generated by OpenCVE AI on October 1, 2026 at 15:52 UTC.

Remediation

Vendor Solution

Update the WordPress hCaptcha for WP plugin to the latest available version (at least 5.4.0).


OpenCVE Recommended Actions

  • Upgrade the hCaptcha for WP plugin to version 5.4.0 or later.
  • If an upgrade cannot be performed immediately, deactivate or remove the hCaptcha for WP plugin to block the bypass.
  • Continuously monitor for new patches from the vendor and apply them as soon as they become available.

Generated by OpenCVE AI on October 1, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Title WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T15:58:15.849Z

Reserved: 2026-09-30T12:43:33.093Z

Link: CVE-2026-103347

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:27.487

Modified: 2026-10-01T16:17:36.040

Link: CVE-2026-103347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:00:11Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing