CVE Vulnerabilities

CVE-2025-1262

Guessable CAPTCHA

Published: Feb 25, 2025 | Modified: Feb 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the Built-in Math Captcha Verification.

Weakness

The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.

Affected Software

Name Vendor Start Version End Version
Advanced_google_recaptcha Webfactoryltd * 1.2.8 (excluding)

Extended Description

An automated attacker could bypass the intended protection of the CAPTCHA challenge and perform actions at a higher frequency than humanly possible, such as launching spam attacks. There can be several different causes of a guessable CAPTCHA:

References