PT-2026-51667 · Jotis · Blue Captcha

Kamil Królikowski

·

Publicado

2026-06-24

·

Atualizado

2026-06-24

·

CVE-2026-10552

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap main page) and on the Hall of Shame and Log subpages, which accept a 'blcap action' / 'action' parameter from $ REQUEST and perform destructive operations (plugin uninstall via blcap uninstall(), log deletion via blcap delete logs(), Hall of Shame deletion via blcap delete ip db(), and adding IPs to the banned list via update option('blcap settings')) with no wp verify nonce(), check admin referer(), or check ajax referer() calls anywhere in the codebase. This makes it possible for unauthenticated attackers to uninstall the plugin, delete audit logs, remove Hall of Shame entries, and add arbitrary IP addresses to the block list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-10552

Produtos afetados

Blue Captcha