plugin

Captchinoo Captcha For Login Form Protection Vulnerabilities

13 known security issues reported for the Captchinoo Captcha For Login Form Protection WordPress plugin. Most recent disclosed May 14, 2021.

2 high

Running Captchinoo Captcha For Login Form Protection on your site? Check whether your installed version is affected.

Scan your site free

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which h...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24191 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attac...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24193 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable p...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24192 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24195 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which he...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24194 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which hel...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24188 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24189 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
May 14, 2021

CVE-2021-24190 on NVD →

Captchinoo, admin login page protection with Google recaptcha <= 2.4 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation

high

The Captchinoo, admin login page protection with Google recaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthen...

CVSS:
8.8
Affected:
up to 2.4
Fixed in:
2.5
Disclosed:
Apr 22, 2021

Captchinoo Captcha <= 2.3 - Missing Authorization to Arbitrary Plugin Installation/Activation

high

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugins from the blog, which help...

CVSS:
8.8
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Apr 22, 2021

CVE-2021-24189 on NVD →

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4

unknown

Arbitrary Plugin Installation and Activation vulnerability discovered by Bugbang in WordPress Captchinoo, Google recaptcha for admin login page plugin (versions <= 2.3).

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Apr 22, 2021

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.5

unknown

The Captchinoo, admin login page protection with Google recaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthen...

Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Apr 22, 2021

Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.5

unknown

The &quot;cp_plugins_do_button_job_later_callback&quot; AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical...

Affected:
up to 2.5
Fixed in:
2.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database