ZeroHour

CVE-2022-2913

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p53
Published
()
Modified
Description

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

Vendors
login no captcha recaptcha project
Products
login no captcha recaptcha
Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.