Input validation vulnerability in reCAPTCHA 1.6

The reCAPTCHA plugin for WordPress is not secure in versions 1.6 and earlier. An attacker with administrator-level access can inject malicious code on pages that will run without the user’s knowledge when the page is opened. This could cause harm to the user’s computer and potentially lead to the attacker gaining control of the user’s information.

Detected in:

reCAPTCHA open vulnerable versions: >= * <= 1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.