CVE-2025-24628
The reCaptcha by BestWebSoft plugin for WordPress is vulnerable to CAPTCHA Bypass in all versions up to, and including, 1.78. This makes it possible for unauthenticated attackers to bypass CAPTCHA.
Source: Wordfence
CVE · Medium
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-24628 | reCaptcha by BestWebSoft [google-captcha] < 1.79 | Authentication Bypass by Spoofing | Medium 5.3 | < 1.79 | 1.79 | 2025-01-03 | — |
The reCaptcha by BestWebSoft plugin for WordPress is vulnerable to CAPTCHA Bypass in all versions up to, and including, 1.78. This makes it possible for unauthenticated attackers to bypass CAPTCHA.
Source: Wordfence
No signup, no credit card — enter your URL and get a security report in seconds.