WPBruiser {no- Captcha anti-Spam} <= 3.1.43 - Unauthenticated PHP Object Injection
highThe WPBruiser {no- Captcha anti-Spam} plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.43 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a PO...
- CVSS:
- 8.1
- Affected:
- up to 3.1.43
- Fix:
- No patched version reported
- Disclosed:
- Aug 5, 2026