Improper Restriction of Excessive Authentication Attempts Vulnerability Affects WP Captcha
CVE-2023-44235

5.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
4 June 2024

Summary

The WP Captcha plugin by Devnath Verma contains a vulnerability that results from improper restriction of excessive authentication attempts. This flaw enables attackers to potentially bypass security measures designed to protect user accounts and sensitive information. If exploited, this vulnerability could lead to unauthorized access, making it essential for users to review their current plugin version and implement necessary updates to safeguard against potential threats. The vulnerability affects all versions from n/a through 2.0.0.

Affected Version(s)

WP Captcha <= 2.0.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

qilin_99 (Patchstack Alliance)
.