Description
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The WordPress plugin Giveaways and Contests by RafflePress before version 1.12.27 leaves the reCAPTCHA secret key embedded in publicly accessible giveaway pages. Unauthenticated visitors can retrieve this key for any active giveaway that has reCAPTCHA configured, exposing sensitive credentials that could be abused for automated captcha solving or other malicious API interactions. This vulnerability results in a direct leakage of secret data that should be kept confidential.

Affected Systems

WordPress sites that use the Giveaways and Contests by RafflePress plugin, with any versions lower than 1.12.27 that have reCAPTCHA enabled on active giveaways. No specific platform versions are listed; the issue applies to any WordPress installation hosting the vulnerable plugin.

Risk and Exploitability

The exploitation requires no authentication and works simply by visiting a public giveaway page containing reCAPTCHA. Because the secret key is exposed to all visitors, the potential for abuse is high. The EPSS score is currently unavailable and the vulnerability is not listed in CISA KEV, but an attacker can immediately obtain the key and potentially use it for further attacks. The lack of a CVSS score limits quantitative assessment, but the known information‑exposure risk combined with easy accessibility suggests a significant threat pending timely patching.

Generated by OpenCVE AI on October 2, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Giveaways and Contests by RafflePress plugin to version 1.12.27 or later, which removes the secret key from public pages.
  • Remove or disable reCAPTCHA from any currently active giveaways until the plugin can be updated.
  • If an update cannot be performed immediately, restrict public access to the giveaway pages or delete the giveaways to prevent the key from being displayed.

Generated by OpenCVE AI on October 2, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 02 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
Title Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T06:00:26.940Z

Reserved: 2026-09-24T11:27:48.588Z

Link: CVE-2026-97317

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T06:16:43.693

Modified: 2026-10-02T06:16:43.693

Link: CVE-2026-97317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T07:30:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor