Unauthenticated Bypass in Captcha Code Plugin by WordPress
CVE-2026-94457

4.8MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 September 2026

What is CVE-2026-94457?

The Captcha Code plugin for WordPress, in versions up to 3.32, suffers from an unauthenticated bypass vulnerability. This flaw allows unauthorized users to circumvent captcha protection mechanisms, potentially enabling malicious actors to exploit other security measures within a website. Website administrators are strongly advised to update the plugin to secure their sites against potential intrusions.

Affected Version(s)

Captcha Code <= 3.32

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KLg | Patchstack Bug Bounty Program
.