First published: Tue Dec 24 2024(Updated: )
The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it possible for unauthenticated attackers to unblock their IP after being locked out due to too many bad password attempts
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
BestWebSoft Google Captcha (reCAPTCHA) for WordPress | <=1.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12034 is classified as a medium severity vulnerability due to the risk of unauthenticated IP unblocking that could impact site security.
To fix CVE-2024-12034, update the Advanced Google reCAPTCHA plugin to version 1.26 or higher, which addresses this vulnerability.
CVE-2024-12034 affects all versions of the Advanced Google reCAPTCHA plugin for WordPress up to and including version 1.25.
CVE-2024-12034 can be exploited by unauthenticated attackers looking to unblock IP addresses.
If exploited, CVE-2024-12034 could allow unauthorized access to unblocked IPs, potentially compromising the security of the website.