Impact
The vulnerability allows an unauthenticated attacker to bypass the CAPTCHA protection that is intended to stop automated form submissions, effectively preventing the plugin from validating user input as genuine. As a result, malicious actors can submit spam, phishing forms, or other unwanted requests without the restrictions normally imposed by the CAPTCHA, thereby compromising the integrity of the form processes. The underlying weakness is an authentication failure (CWE‑290).
Affected Systems
WordPress sites that have the CAPTCHA 4WP plugin from the vendor WPKube installed with a version of 7.6.0 or lower are affected. Any site using an unreleased or older build of the plugin remains vulnerable until the fix is applied. Users of newer versions (greater than 7.6.0) are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No exploit probability is available, and the vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is remote and unauthenticated; an attacker only needs to send a crafted request to the form that is protected by the plugin to achieve the bypass. Because no privileged access or additional credentials are required, the risk to affected sites is relatively high for attackers intent on flooding, spamming, or phishing.
OpenCVE Enrichment