plugin

Is Human Vulnerabilities

4 known security issues reported for the Is Human WordPress plugin. Most recent disclosed Oct 15, 2025.

1 critical

Running Is Human on your site? Check whether your installed version is affected.

Scan your site free

is_human() [is-human] <= 1.4.2 (closed)

unknown

[en] The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter is set to 'log-reset'. The root cause is unsafe use of eval() on user-controlled input, which can lead to execution of attacker-supplie...

Affected:
up to 1.4.2
Fixed in:
1.4.2
Disclosed:
Oct 15, 2025

CVE-2011-10033 on NVD →

is_human() [is-human] < 1.4.3 (closed)

unknown

The vulnerability exists in /is-human/engine.php. It takes control of the eval() function via the "type" parameter, when the "action" is set to log-reset.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
May 17, 2011

is-human <= 1.4.2 - Unauthenticated Remote Code Execution

critical

The is-human plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.2 via the /plugins/is-human/engine.php file. This is due to the plugin accepting user-supplied input passed to eval(). This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 1.4.2
Fix:
No patched version reported
Disclosed:
May 16, 2011

CVE-2011-10033 on NVD →

is_human() [is-human] <= 1.4.2 (unfixed + closed)

unknown

The is-human WordPress plugin was affected by a Remote Comm&amp; Execution security vulnerability.

Affected:
up to 1.4.2
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database