CVE-2026-39772: WordPress Captcha by BestWebSoft plugin <= 5.2.8 - Bypass Vulnerability vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
Affected Software
1 affected component
Bestwebsoft Captcha by BestWebSoft<=5.2.8
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
2
Which installations are affected?
Captcha by BestWebSoft versions 5.2.8 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration is required.
3
What is the security impact of a successful exploit?
The reported CVSS vector indicates integrity impact only, with no reported confidentiality or availability impact. The issue is described as a CAPTCHA bypass, but the provided information does not identify which protected action or form can be bypassed.