CVE-2026-94457: WordPress Captcha Code plugin <= 3.32 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Captcha Code pluginto a version that resolves this vulnerability.Fixed in 3.33
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges. Exploitation is network-accessible, although the high attack-complexity rating indicates additional conditions or steps are required.
What security impact is indicated?
Successful exploitation may result in limited confidentiality and integrity impact. No availability impact is indicated by the supplied CVSS vector.
Which plugin versions are affected?
Captcha Code plugin versions up to and including 3.32 are identified as affected. The provided data does not specify a fixed version or workaround.