PT-2026-1592 · WordPress · Recaptcha Wordpress Plugin

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2025-13520

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MTCaptcha WordPress Plugin versions prior to 2.7.3
Description The software is susceptible to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the settings update functionality. An unauthenticated attacker could potentially update plugin settings, including sensitive values like the private key, by tricking a site administrator into performing an action. The attack requires the administrator to click a malicious link.
Recommendations Update the MTCaptcha WordPress Plugin to version 2.7.3 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-13520

Affected Products

Recaptcha Wordpress Plugin