First published: Tue Feb 25 2025(Updated: )
The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the Built-in Math Captcha Verification.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Webfactoryltd Advanced Google Recaptcha Wordpress | <1.2.8 | |
Google reCAPTCHA | <=1.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1262 is classified as a high severity vulnerability due to its potential to allow unauthorized access.
To fix CVE-2025-1262, update the Advanced Google reCaptcha plugin for WordPress to version 1.28 or later.
CVE-2025-1262 affects the Advanced Google reCaptcha plugin versions up to and including 1.27.
CVE-2025-1262 can be exploited by unauthenticated attackers to bypass CAPTCHA verification.
CVE-2025-1262 allows attackers to bypass CAPTCHA protection, potentially leading to form abuse and spam.