Описание
The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
Ссылки
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7 (исключая)
cpe:2.3:a:login_no_captcha_recaptcha_project:login_no_captcha_recaptcha:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 29%
0.00102
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 4.3
github
больше 3 лет назад
The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
EPSS
Процентиль: 29%
0.00102
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-639