{"error":0,"message":null,"data":{"name":"Captcha","plugin":"captcha","link":"https:\/\/wordpress.org\/plugins\/captcha\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"0732390f2ac3591417c2757cd0bea383bb7ebbfbef0c424af377eaf5b0b814fe","name":"Captcha [captcha] < 4.0.7 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.7","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2014-9283","name":"CVE-2014-9283","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9283","description":"[en] The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.","date":"2015-03-03"},{"id":"JVNDB-2015-000029","name":"BestWebSoft Captcha plugin vulnerable to CAPTCHA authentication bypass","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2015-000029","description":"Captcha provided by BestWebSoft is a plugin for WordPress. Captcha contains a CAPTCHA authentication bypass vulnerability (CWE-254).","date":"2015-03-03"},{"id":"22b32215ad693e41c4efce8b0db1cfa4e654f53d","name":"WordPress Captcha Plugin <= 4.0.6 - BYPASS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/captcha\/vulnerability\/wordpress-captcha-plugin-4-0-6-bypass","description":"Because of this vulnerability, remote attackers can bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.\nUpdate the plugin.","date":"2014-12-05"},{"id":"4c130fbb-e517-4a87-b38a-49448e17f661","name":"Captcha &lt;= 4.0.6 - Captcha Bypass","link":"https:\/\/wpscan.com\/vulnerability\/4c130fbb-e517-4a87-b38a-49448e17f661","description":"The captcha WordPress plugin was affected by a Captcha Bypass security vulnerability.","date":null},{"id":"2305c944ec211fc7db9a5eb4c42da794d7998e8f","name":"BestWebSoft Captcha <= 4.0.6 - CAPTCHA Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/captcha-bws\/bestwebsoft-captcha-406-captcha-bypass","description":"The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.","date":"2014-12-05"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"}}},{"uuid":"b1ce3f388dcdcef208dd289de9bb7f29cafe772f449367d0e6bc929ce0c0b5b2","name":"Captcha [captcha] < 2.6 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2008-0206","name":"CVE-2008-0206","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2008-0206","description":"[en] Multiple cross-site scripting (XSS) vulnerabilities in captcha\\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.","date":"2008-01-10"},{"id":"7fae5a241e81f8ef04a6ee3e091303068bf5ac7c","name":"WordPress  Captcha Plugin <= 2.5 - Multiple XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/captcha\/vulnerability\/wordpress-captcha-plugin-2-5-multiple-xss","description":"Because of these vulnerabilities, the attackers can inject arbitrary web script or HTML.","date":"2008-01-09"},{"id":"e22a7b86aca83fa3e258f0447085ee1b5f964d2e","name":"Captcha! <= 2.5d - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/captcha-offrepo\/captcha-25d-cross-site-scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in captcha\\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.","date":"2007-11-26"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"e0ed14b57e1c5708f594c875ae0188ef7c873622b8d75f6f1c8388c0acbd39e0","name":"Captcha [captcha] < 4.3.0 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.0","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2017-2171","name":"CVE-2017-2171","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-2171","description":"[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2, Custom Search prior to version 1.36, Donate prior to version 2.1.1, Email Queue prior to version 1.1.2, Error Log Viewer prior to version 1.0.6, Facebook Button prior to version 2.54, Featured Posts prior to version 1.0.1, Gallery Categories prior to version 1.0.9, Gallery prior to version 4.5.0, Google +1 prior to version 1.3.4, Google AdSense prior to version 1.44, Google Analytics prior to version 1.7.1, Google Captcha (reCAPTCHA) prior to version 1.28, Google Maps prior to version 1.3.6, Google Shortlink prior to version 1.5.3, Google Sitemap prior to version 3.0.8, Htaccess prior to version 1.7.6, Job Board prior to version 1.1.3, Latest Posts prior to version 0.3, Limit Attempts prior to version 1.1.8, LinkedIn prior to version 1.0.5, Multilanguage prior to version 1.2.2, PDF & Print prior to version 1.9.4, Pagination prior to version 1.0.7, Pinterest prior to version 1.0.5, Popular Posts prior to version 1.0.5, Portfolio prior to version 2.4, Post to CSV prior to version 1.3.1, Profile Extra prior to version 1.0.7. PromoBar prior to version 1.1.1, Quotes and Tips prior to version 1.32, Re-attacher prior to version 1.0.9, Realty prior to version 1.1.0, Relevant - Related Posts prior to version 1.2.0, Sender prior to version 1.2.1, SMTP prior to version 1.1.0, Social Buttons Pack prior to version 1.1.1, Subscriber prior to version 1.3.5, Testimonials prior to version 0.1.9, Timesheet prior to version 0.1.5, Twitter Button prior to version 2.55, User Role prior to version 1.5.6, Updater prior to version 1.35, Visitors Online prior to version 1.0.0, and Zendesk Help Center prior to version 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the function to display the BestWebSoft menu.","date":"2017-05-22"},{"id":"JVNDB-2017-000094","name":"Multiple BestWebSoft WordPress plugins vulnerable to cross-site scripting","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2017-000094","description":"Multiple WordPress Plugins provided by BestWebSoft use a common function for displaying the BestWebSoft menu. This function contains a cross-site scripting vulnerability (CWE-79).  Chris Liu reported this vulnerability to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.","date":"2017-05-16"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-91","name":"XML Injection (aka Blind XPath Injection)","description":"The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system."}]}},{"uuid":"06d81598dba7f2d5e2089d1ffc71b99e293efdbdac8cb1ae3d241d3811c9ca3c","name":"Captcha [captcha] < 4.4.5 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.5","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"e40201b62902ae65b8a1a70d24b243a1da5127e0","name":"WordPress Captcha plugin <=4.4.4 - Backdoored","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/captcha\/vulnerability\/wordpress-captcha-plugin-4-4-4-backdoored","description":"Backdoor found by WordFence team in WordPress Captcha plugin (versions 4.3.6\u20134.4.4).","date":"2017-12-20"}],"impact":[]},{"uuid":"7b07033739971de1696b98aab5adf66e976450eca6047d85daf202e8a535a609","name":"Captcha [captcha] < 4.1.6 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.6","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"390a260bfed344d55addf90dfd55f04e535a170c","name":"WordPress Best Web Soft Captcha Plugin 4.1.5 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/captcha\/vulnerability\/wordpress-best-web-soft-captcha-plugin-4-1-5-multiple-vulnerabilities","description":"There are multiple vulnerabilities in this plugin, such as XSS and CSRF. Because of that, an attacker can send admin a URL crafted (for the example, http:\/\/wwww.victim.com\/wp-admin\/admin.php?page=captcha.php&action=whitelist&s=%3Cscript%3Ealert%281%29%3B%3C%2Fscript%3E) or send a form, that will execute XSS.\nUpgrade the plugin.","date":"2016-03-10"}],"impact":[]},{"uuid":"a4ecb9bb057e0d700c1f6bc645dc864bc4941ee771a87ee587cced996827ab2a","name":"Captcha [captcha] < 3.8.2 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.2","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"1d43e0c012d228f327428a65d35adc0a20f09237","name":"WordPress Captcha Plugin <= 3.8.1 -  Bypass","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/captcha\/vulnerability\/wordpress-captcha-plugin-3-8-1-bypass","description":"This plugin is prone to a BYPASS vulnerability.\nUpdate the plugin.","date":"2014-08-01"}],"impact":[]},{"uuid":"7740f2cba0b98c5b16519d5d140c2c1a5f51fafce474113dd539a2abe44285ca","name":"Captcha [captcha] < 4.3.0 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.0","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"efd816c3-90d4-40bf-850a-0e4c1a756694","name":"Multiple BestWebSoft Plugins - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/efd816c3-90d4-40bf-850a-0e4c1a756694","description":null,"date":null}],"impact":[]},{"uuid":"7069d4cbc780e70208eb2cd43dd0cfec63e12869d407dd79ab95df752544215d","name":"Captcha [captcha] >= 4.3.6 - >= 4.4.4 (closed)","description":null,"operator":{"min_version":"4.3.6","min_operator":"ge","max_version":"4.4.4","max_operator":"ge","unfixed":"0","closed":"1"},"source":[{"id":"1e95d819-5034-48d4-b5fc-94bf5b2534f2","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/1e95d819-5034-48d4-b5fc-94bf5b2534f2","description":null,"date":null}],"impact":[]},{"uuid":"ae6aa696b279364570fc0a73998142f5a09475db04313428cfc030640d297f57","name":"Captcha [captcha] >= 2.12 - <= 3.8.1 (closed)","description":null,"operator":{"min_version":"2.12","min_operator":"ge","max_version":"3.8.1","max_operator":"le","unfixed":"0","closed":"1"},"source":[{"id":"66aaabac-a78c-467f-9de2-8b2f642ca913","name":"Captcha 2.12-3.8.1 - Captcha Bypass","link":"https:\/\/wpscan.com\/vulnerability\/66aaabac-a78c-467f-9de2-8b2f642ca913","description":"The captcha WordPress plugin was affected by a Captcha Bypass security vulnerability.","date":null}],"impact":[]},{"uuid":"58a4813c7c0fdb3930f2e7f46f299fa01e69898f87408422a59a203b346b9a22","name":"Captcha [captcha] >= 4.3.6 - <= 4.4.4","description":null,"operator":{"min_version":"4.3.6","min_operator":"ge","max_version":"4.4.4","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"b28b2858a9a792b9c1bbae222d54276268f3aa1a","name":"Captcha 4.3.6 - 4.4.4 - Plugin Backdoor","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/captcha\/captcha-436-444-plugin-backdoor","description":"The Captcha plugin for WordPress contained a backdoor that injected SEO spam into unsuspecting users WordPress sites in version 4.3.6 to 4.4.4.","date":"2017-12-19"}],"impact":[]},{"uuid":"54f4fa42afcdf078b13eb537b8e813a03dec432eccd6e2894990bab813e7373c","name":"Captcha [captcha] < 4.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"af3c58f096e3356bc77e2a9c70aa60f25484d354","name":"Captcha < 4.3.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/captcha\/captcha-430-reflected-cross-site-scripting","description":"The Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018category\u2019 parameter in versions before 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2017-04-12"}],"impact":[]},{"uuid":"1919684100a987fcc85cd8ebfd68ee022c158256537ec40897966bb59737ff7b","name":"Captcha [captcha] < 3.8.2 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.2","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"a9819ffff49fd7ace1475add14a4d66bf3932d64","name":"Captcha <= 3.8.1 - Captcha Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/captcha\/captcha-381-captcha-bypass","description":"The Captcha plugin for WordPress is vulnerable to captcha bypass in versions up to, and including, 3.8.1.","date":"2014-08-01"}],"impact":[]}]},"updated":"1672766455"}