Impact
An unauthenticated bypass vulnerability exists in the hCaptcha for WP plugin versions 5.3.0 and earlier. The flaw permits an attacker to bypass authentication checks that the plugin normally enforces, enabling unauthorized interactions with the plugin’s protected features. This issue is classified as CWE-290, indicating an authentication bypass. Successful exploitation could compromise the confidentiality and integrity of the WordPress site and may serve as a foothold for subsequent attacks.
Affected Systems
The affected product is the hCaptcha for WP plugin by hCaptcha, with vulnerability present in versions up to and including 5.3.0. Site administrators using these versions are impacted; later versions are not affected.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability represents a moderate risk, and its EPSS score is currently unavailable, leaving exploitation frequency uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s form interfaces exposed on a WordPress site; an attacker can send crafted requests to the form endpoints to trigger the bypass. Because the flaw does not require authentication, attackers can perform the exploit without prior credentials, making it accessible to anyone who can reach the affected site.
OpenCVE Enrichment