Blue Captcha

Blue Captcha has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

2 independent researchers contributed these findings, one record each. Blue Captcha is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Blue Captcha vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2026-10552

Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv2.1.0

Blue Captcha

jotis

Author

jotis

4.7(15)
94/100
Last Updated
2026-08-17 (26d ago)
Active Installs
400+
Downloads
37,937
Requires WP
4.9+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2012-03-19 (15y ago)

Blue Captcha is a powerful and highly customized WordPress plugin that effectively protects your WP blogs from spammers and unwanted persons. It is easily installed and provides high protection against spammers, bots or unwanted persons. Do you like Blue Captcha? Then Support it! If you like Blue Captcha, then you can help it grow by donating one dollar. Any donation will be highly appreciated and will help in further development of this plugin. Features: It can be applied to any of the following : login form, registration form, commentary form or password recovery form It’s highly customized It has 7 predefined CAPTCHA difficulty levels to choose from – of course, you can adjust your CAPTCHA settings and create a custom level The possible CAPTCHA customizations are more than enough It can apply the same or totally different CAPTCHA settings on login form, registration form, commentary form and password recovery form It can display CAPTCHA to only non-registered users or registered users It can preview CAPTCHA image before applying it It supports 5 different fonts and 30 different background images It supports single or double CAPTCHA layer It can display up to 20(!) characters on Captcha Images It is capable of adding extra drawing (lines, circles, grid, transparent lines) on CAPTCHA image It is capable of keeping log file which registers all activities concerning user logins, user registrations, user comments and password recovery It has “Hall of Shame” (HoS) It provides blocking options as well It can export the entire log file or HoS into CSV file (Excel) With the help of log file and HoS, it’s easy to track down the IP address of spammers or unwanted persons and ban them for ever You can visit Blue Captcha Page for more information. Blue Captcha Translation Blue Captcha is now available in Greek, Spanish, Russian, Italian, Brazilian Portuguese, Serbo-Croatian, Slovenian and Arabic. I would be very grateful if someone is willing to translate Blue Captcha to another language. For those interested, the template translation file (“blue-captcha.pot”) is located on “languages” folder of blue-captcha plugin. Contribution Special Thanks To The Following Contributors: Leon Roskar (http://www.qb.si) => Slovenian Translation Borisa Djuraskovic (http://www.webhostinghub.com) => Serbo-Croatian Translation João Victor T. Magalhães => Brazilian Portuguese Translation Ericka Morales Hernández (http://todoriesgo.net) => Italian Translation Alex Balashov => Russian Translation Andrew Kurtis (http://www.webhostinghub.com) => Spanish Translation Christos Bakopoulos => Arabic Translation

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C