FunCaptcha – Anti-Spam CAPTCHA < 0.3.3 - Cross-Site Request Forgery
highThe FunCaptcha – Anti-Spam CAPTCHA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.3.3. This is due to missing or incorrect nonce validation on the funcaptcha_get_settings_post function. This makes it possible for unauthenticated attackers to manipulate plugin settings via a forged...
- CVSS:
- 8.8
- Affected:
- up to 0.3.3
- Fixed in:
- 0.3.3
- Disclosed:
- Apr 11, 2014