Captcha Code
Captcha Code has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 2 are fixed as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Guessable CAPTCHA.
Every one of the 2 issues recorded for Captcha Code has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Captcha Code is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-37411Captcha Code <= 2.7 - Cross-Site Request Forgery to Plugin Settings Update
Read the full analysisVulnerability Records

Captcha Code
Author
WebFactory
Captcha adds GDPR compatible captcha code anti-spam protection (like Google ReCaptcha) to WordPress forms – comments form, registration form, lost password form, and login form. In order to post comments or register, users have to type in the code shown on the image. This prevents spam from automated bots & adds security. No external services (like Google ReCaptcha) are used. No API keys are needed, and no user-identifiable data is used so it’s GDPR compatible. Features Captcha position – comments form, login form, registration form, or lost password form. Letters type – capital letters, small letters, or captial & small letters. Captcha type – alphanumeric, alphabets or numbers. Translation enabled.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C