IP Address Spoofing Vulnerability in Login No Captcha reCAPTCHA WordPress Plugin

IP Address Spoofing Vulnerability in Login No Captcha reCAPTCHA WordPress Plugin

CVE-2022-2913 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

Learn more about our Wordpress Pen Testing.