Ajax BootModal Login <= 1.4.3 - CAPTCHA Reuse

2018-08-26 00:00
Lydéric Lefebvre

Strategic Overview

Status
Unpatched
Affected PluginAjax BootModal Login
Affected Version<= 1.4.3
CVSS5.3Medium
CVECVE-2018-15876
View all Ajax BootModal Login vulnerabilities

Vulnerability Overview

An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and password-recovery form require solving a CAPTCHA to perform actions. However, this is required only once per user session, and therefore one could send as many requests as one wished by automation.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C