BestWebSoft Google Captcha Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability allowing identity spoofing has been identified in the BestWebSoft Google Captcha WordPress plugin, affecting versions through 1.78. This vulnerability allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access or actions.

Impact

Exploiting this vulnerability could allow attackers to bypass authentication, leading to unauthorized access or actions on behalf of a user.

Remediation

Users of the BestWebSoft Google Captcha WordPress plugin should update to version 1.79 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.