WordPress security by component
Advanced Google reCAPTCHA
Plugin description
Advanced Google reCAPTCHA is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jun 05, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
advanced-google-recaptchaLatest vulnerability
CVE-2026-5415: Advanced Google reCAPTCHA: Privilege escalation or authentication bypass
Advanced Google reCAPTCHA is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.38. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Jun 05, 2026 |
CVE-2026-5415
Advanced Google reCAPTCHA: Privilege escalation or authentication bypass
Advanced Google reCAPTCHA is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.38. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jun 05, 2026 |
CVE-2026-5411
Advanced Google reCAPTCHA: Dangerous file upload
Advanced Google reCAPTCHA is affected by dangerous file upload. Exploitation requires an authenticated subscriber account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 5.38. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
5.39 |
CVE8.8
NVDPending
|
| Mar 28, 2025 |
CVE-2025-2074
Advanced Google reCAPTCHA: SQL injection
Advanced Google reCAPTCHA is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 25, 2025 |
CVE-2025-1262
Advanced Google reCaptcha: A security weakness
Advanced Google reCaptcha is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 24, 2024 |
CVE-2024-12034
Advanced Google reCAPTCHA: A security weakness
Advanced Google reCAPTCHA is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|