First published: Fri Sep 16 2022(Updated: )
The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google reCAPTCHA | <1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2913 is classified as a critical vulnerability due to the potential for unauthorized access to the login system.
To fix CVE-2022-2913, you should update the Login No Captcha reCAPTCHA WordPress plugin to version 1.7 or later.
CVE-2022-2913 affects users of the Login No Captcha reCAPTCHA plugin for WordPress versions prior to 1.7.
CVE-2022-2913 allows attackers to spoof allowed IP addresses and bypass the CAPTCHA verification on the login screen.
There is currently no publicly available information indicating that CVE-2022-2913 is being actively exploited in the wild.