CVE-2025-24628: WordPress reCaptcha by BestWebSoft Plugin <= 1.78 - Captcha Bypass vulnerability
Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24628?
CVE-2025-24628 is considered a high severity vulnerability due to its potential for identity spoofing.
How do I fix CVE-2025-24628?
To fix CVE-2025-24628, update BestWebSoft Google Captcha and BestWebSoft WordPress reCaptcha to the latest version beyond 1.78.
What does CVE-2025-24628 impact?
CVE-2025-24628 impacts BestWebSoft Google Captcha and BestWebSoft WordPress reCaptcha versions from unspecified up to 1.78.
What is the nature of the vulnerability in CVE-2025-24628?
CVE-2025-24628 is an authentication bypass vulnerability that allows for identity spoofing.
Is there a known exploit for CVE-2025-24628?
While specific exploits may not be publicly detailed, the nature of the vulnerability indicates a risk of exploitation through spoofing.