VYPR

Login No Captcha reCAPTCHA

by WordPress

CVEs (2)

  • CVE-2026-2374HigMay 28, 2026
    risk 0.47cvss 7.2epss

    The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of…

  • CVE-2022-2913Sep 16, 2022
    risk 0.00cvss epss 0.00

    The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.