Impact
The WordPress plugin Giveaways and Contests by RafflePress before version 1.12.27 leaves the reCAPTCHA secret key embedded in publicly accessible giveaway pages. Unauthenticated visitors can retrieve this key for any active giveaway that has reCAPTCHA configured, exposing sensitive credentials that could be abused for automated captcha solving or other malicious API interactions. This vulnerability results in a direct leakage of secret data that should be kept confidential.
Affected Systems
WordPress sites that use the Giveaways and Contests by RafflePress plugin, with any versions lower than 1.12.27 that have reCAPTCHA enabled on active giveaways. No specific platform versions are listed; the issue applies to any WordPress installation hosting the vulnerable plugin.
Risk and Exploitability
The exploitation requires no authentication and works simply by visiting a public giveaway page containing reCAPTCHA. Because the secret key is exposed to all visitors, the potential for abuse is high. The EPSS score is currently unavailable and the vulnerability is not listed in CISA KEV, but an attacker can immediately obtain the key and potentially use it for further attacks. The lack of a CVSS score limits quantitative assessment, but the known information‑exposure risk combined with easy accessibility suggests a significant threat pending timely patching.
OpenCVE Enrichment