Impact
An unauthenticated bypass flaw exists in WordPress Captcha Code plugin versions 3.32 and earlier, allowing an attacker to bypass the captcha verification step and gain unauthorized access to protected actions. This vulnerability arises from improper authentication handling (CWE‑290). Consequently, attackers could circumvent login restrictions or submit forms without completing captcha validation, resulting in unauthorized data manipulation or exfiltration.
Affected Systems
The flaw affects the WordPress Captcha Code plugin sold by WebFactory. Any WordPress site running Captcha Code version 3.32 or earlier is vulnerable. No specific WordPress core versions are mentioned, so all affected plugin versions are at risk.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote through HTTP requests to the plugin's verification endpoints, as the bypass occurs with unauthenticated traffic. Even though no active exploits are reported, the flaw can be leveraged by anyone who can reach the site to override captcha checks.
OpenCVE Enrichment