Input validation vulnerability in Captchinoo, admin login page protection with Google recaptcha 2.4

The Captchinoo plugin for WordPress (admin login page protection with Google recaptcha) is not completely secure in versions up to 2.4. This is because there is missing or incorrect validation on the ‘cp_plugins_do_button_job_later_callback’ AJAX action. This means that unauthenticated attackers can potentially install and activate other plugins if they can trick a site administrator into clicking a link or doing something similar.

Detected in:

Captchinoo, admin login page protection with Google recaptcha fixed vulnerable versions: >= * <= 2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.