Description
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
Published: 2026-09-23
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

An unauthenticated bypass flaw exists in WordPress Captcha Code plugin versions 3.32 and earlier, allowing an attacker to bypass the captcha verification step and gain unauthorized access to protected actions. This vulnerability arises from improper authentication handling (CWE‑290). Consequently, attackers could circumvent login restrictions or submit forms without completing captcha validation, resulting in unauthorized data manipulation or exfiltration.

Affected Systems

The flaw affects the WordPress Captcha Code plugin sold by WebFactory. Any WordPress site running Captcha Code version 3.32 or earlier is vulnerable. No specific WordPress core versions are mentioned, so all affected plugin versions are at risk.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote through HTTP requests to the plugin's verification endpoints, as the bypass occurs with unauthenticated traffic. Even though no active exploits are reported, the flaw can be leveraged by anyone who can reach the site to override captcha checks.

Generated by OpenCVE AI on September 23, 2026 at 20:11 UTC.

Remediation

Vendor Solution

Update the WordPress Captcha Code plugin to the latest available version (at least 3.33).


OpenCVE Recommended Actions

  • Update the WordPress Captcha Code plugin to version 3.33 or later
  • If captcha is not required, disable or delete the plugin to eliminate the attack surface
  • Replace the Captcha Code plugin with a different captcha solution that has no known authentication bypass flaws
  • Keep the WordPress core and all other plugins updated to mitigate related vulnerabilities

Generated by OpenCVE AI on September 23, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
Title WordPress Captcha Code plugin <= 3.32 - Bypass Vulnerability vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T19:43:23.776Z

Reserved: 2026-09-21T17:14:49.494Z

Link: CVE-2026-94457

cve-icon Vulnrichment

Updated: 2026-09-23T19:04:58.623Z

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:49.253

Modified: 2026-09-23T20:17:24.047

Link: CVE-2026-94457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:15:09Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing