CVE · High

CVE-2026-5415 — Advanced Google reCAPTCHA [advanced-google-recaptcha] < 5.39

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5415 Advanced Google reCAPTCHA [advanced-google-recaptcha] < 5.39 Authentication Bypass Using an Alternate Path or Channel High 8.8 < 5.39 5.39 2026-06-05

CVE-2026-5415

A security flaw exists in WP Captcha PRO plugin versions up to 5.38 that allows unauthorized login through a specific vulnerability. This occurs because the plugin doesn't check user permissions when handling temporary links generated by create_temporary_link tool, and instead relies on a nonce check which is accessible to all backend users. As a result, attackers with Subscriber-level access can exploit this weakness to gain full account control over any WordPress user, including Administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.