plugin

Login Recaptcha Vulnerabilities

2 known security issues reported for the Login Recaptcha WordPress plugin. Most recent disclosed May 27, 2026.

1 high 1 medium

Running Login Recaptcha on your site? Check whether your installed version is affected.

Scan your site free

Login No Captcha reCAPTCHA <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting via PHP_SELF

high

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['PHP_SELF'])` in the `login_nocaptcha...

CVSS:
7.2
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
May 27, 2026

CVE-2026-2374 on NVD →

Login No Captcha reCAPTCHA <= 1.6.11 - CAPTCHA Bypass via Whitelisted IP Address Spoofing

medium

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.6.11. This is due to the whitelisted IP address functionality relying on user-supplied IP addresses from an HTTP Header. If an attacker can gain access to a whitelisted IP address they can spoof the r...

CVSS:
5.3
Affected:
up to 1.6.11
Fixed in:
1.7
Disclosed:
Aug 16, 2022

CVE-2022-2913 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database