CVE-2026-103347: WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability
Published Oct 1, 2026
·Updated
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Affected Software
1 affected component
hCaptcha hCaptcha for WP<=5.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
hCaptcha for WPto a version that resolves this vulnerability.Fixed in 5.4.0
Event History
Oct 1, 2026
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
2
Which deployments are affected?
Affected versions are hCaptcha for WP through 5.3.0. The provided information does not identify any configuration prerequisite or exception.
3
What is the likely security impact?
The vulnerability allows a bypass and is rated medium severity with an integrity impact of low. The supplied data reports no confidentiality or availability impact.