Input validation vulnerability in Advanced Google reCAPTCHA 1.29

The Google reCAPTCHA plugin for WordPress has a security vulnerability that allows hackers to access sensitive information from the database. This vulnerability occurs in all versions of the plugin up to and including 1.29. The problem lies in the way the plugin handles user input, which allows attackers with Subscriber-level access or higher to add their own SQL queries to the existing ones. This is particularly dangerous when the plugin’s settings page has not been visited and the welcome message has not been dismissed.

Detected in:

Advanced Google reCAPTCHA fixed vulnerable versions: >= * <= 1.29

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.