CVE-2025-24628

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 27, 2025
CWE ID 290

Summary

CVE-2025-24628 is a newly disclosed vulnerability affecting BestWebSoft Google Captcha, a plugin used for adding reCAPTCHA functionality to WordPress websites. The issue permits authentication bypass through identity spoofing. Attackers can exploit this vulnerability by manipulating the Captcha mechanism, allowing unauthorized access to protected areas on affected sites. Plugins versions from n/a up to 1.78 are vulnerable to this exploit.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share