Advanced Google reCAPTCHA
Advanced Google reCAPTCHA has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 5 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Authentication Bypass Using An Alternate Path Or Channel, behind 1 of the records (20%). Other recurring categories include Generation Of Predictable Numbers Or Identifiers, Guessable CAPTCHA.
Every one of the 5 issues recorded for Advanced Google reCAPTCHA has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by Max Boll (_b0lli). Advanced Google reCAPTCHA is installed on roughly 200,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-5415WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link
Read the full analysisVulnerability Records

Advanced Google reCAPTCHA
Author
WebFactory
Advanced Google reCAPTCHA protects your WordPress site from spam comments & brute force login attacks using captcha. This captcha plugin, quickly adds Google reCAPTCHA and other captcha tests to WordPress comment form, login form, and other forms. Using Advanced Google reCAPTCHA (most popular captcha on the market), you’ll be safe from spam comments and protect user accounts, WooCommerce, Easy Digital Downloads, BuddyPress and other forms from brute-force login attacks. reCaptcha works for: Login Form Registration Form Reset Password Form Comment Form BuddyPress Form WooCommerce Form Easy Digital Downloads (EDD) Login Form Easy Digital Downloads (EDD) Registration Form Captcha uses these 3rd party libs: Chart.js, 2017 Nick Downie, MIT DataTables, 2008-2017 SpryMedia Ltd, MIT moment.js, Tim Wood, Iskren Chernev, MIT SweetAlert 2, github.com/Sweetalert2/Sweetalert2, MIT tooltipster, www.heteroclito.fr/modules/tooltipster/, MIT
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C