CVE · Medium

CVE-2024-12034 — Advanced Google reCAPTCHA [advanced-google-recaptcha] < 1.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12034 Advanced Google reCAPTCHA [advanced-google-recaptcha] < 1.26 Generation of Predictable Numbers or Identifiers Medium 5.3 < 1.26 1.26 2024-12-23

CVE-2024-12034

The Advanced Google reCAPTCHA plugin for WordPress before version 1.26 contains a weakness in its IP blocking mechanism that allows unauthenticated users to bypass lockouts. The vulnerability stems from the plugin's use of insufficiently random keys when creating unblock requests, enabling attackers who have been temporarily blocked after multiple failed login attempts to regain access without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.