VYPR

Login Recaptcha

by WordPress

CVEs (1)

  • CVE-2026-2374HigMay 28, 2026
    risk 0.47cvss 7.2epss

    The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of…