Advanced Google reCaptcha WordPress Plugin CAPTCHA Bypass Vulnerability

Vulnerability

A CAPTCHA bypass vulnerability has been identified in the Advanced Google reCaptcha plugin for WordPress, affecting versions through 1.27. This vulnerability allows unauthenticated attackers to bypass the built-in math CAPTCHA verification, potentially leading to spam comments or automated form submissions.

Impact

Exploitation of this vulnerability allows for the bypass of math CAPTCHA verification, which could lead to an increase in spam comments or automated form submissions.

Remediation

Users are advised to update the Advanced Google reCaptcha plugin to version 1.28 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.