Captcha 4.3.6 - 4.4.4 - Plugin Backdoor

2017-12-19 00:00
Matt Barry

Strategic Overview

Status
Patched in 4.4.5
Affected PluginCaptcha
Affected Version4.3.6 – 4.4.4
CVSS9.6Critical
CVEN/A
View all Captcha vulnerabilities

Vulnerability Overview

The Captcha plugin for WordPress contained a backdoor that injected SEO spam into unsuspecting users WordPress sites in version 4.3.6 to 4.4.4.

Technical Analysis

REMEDIATION: Update to version 4.4.5, or a newer patched version --- IDENTIFIER: CWE-912 (Hidden Functionality) The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C