Improper Restriction of Excessive Authentication Attempts Vulnerability Affects WP Captcha
CVE-2023-44235
5.3MEDIUM
Summary
The WP Captcha plugin by Devnath Verma contains a vulnerability that results from improper restriction of excessive authentication attempts. This flaw enables attackers to potentially bypass security measures designed to protect user accounts and sensitive information. If exploited, this vulnerability could lead to unauthorized access, making it essential for users to review their current plugin version and implement necessary updates to safeguard against potential threats. The vulnerability affects all versions from n/a through 2.0.0.
Affected Version(s)
WP Captcha <= 2.0.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
qilin_99 (Patchstack Alliance)