is_human() [is-human] <= 1.4.2 (closed)
unknown
[en] The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter is set to 'log-reset'. The root cause is unsafe use of eval() on user-controlled input, which can lead to execution of attacker-supplie...
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Oct 15, 2025
CVE-2011-10033 on NVD →
is_human() [is-human] < 1.4.3 (closed)
unknown
The vulnerability exists in /is-human/engine.php. It takes control of the eval() function via the "type" parameter, when the "action" is set to log-reset.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- May 17, 2011
is-human <= 1.4.2 - Unauthenticated Remote Code Execution
critical
The is-human plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.2 via the /plugins/is-human/engine.php file. This is due to the plugin accepting user-supplied input passed to eval(). This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2011
CVE-2011-10033 on NVD →
is_human() [is-human] <= 1.4.2 (unfixed + closed)
unknown
The is-human WordPress plugin was affected by a Remote Comm& Execution security vulnerability.
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database