Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which h...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24191 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attac...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24193 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable p...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24192 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24195 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which he...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24194 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which hel...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24188 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24189 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- May 14, 2021
CVE-2021-24190 on NVD →
Captchinoo, admin login page protection with Google recaptcha <= 2.4 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
high
The Captchinoo, admin login page protection with Google recaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthen...
- CVSS:
- 8.8
- Affected:
- up to 2.4
- Fixed in:
- 2.5
- Disclosed:
- Apr 22, 2021
Captchinoo Captcha <= 2.3 - Missing Authorization to Arbitrary Plugin Installation/Activation
high
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugins from the blog, which help...
- CVSS:
- 8.8
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Apr 22, 2021
CVE-2021-24189 on NVD →
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.4
unknown
Arbitrary Plugin Installation and Activation vulnerability discovered by Bugbang in WordPress Captchinoo, Google recaptcha for admin login page plugin (versions <= 2.3).
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Apr 22, 2021
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.5
unknown
The Captchinoo, admin login page protection with Google recaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthen...
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- Apr 22, 2021
Captchinoo, admin login page protection with Google recaptcha [captchinoo-captcha-for-login-form-protection] < 2.5
unknown
The "cp_plugins_do_button_job_later_callback" AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical...
- Affected:
- up to 2.5
- Fixed in:
- 2.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database