Captcha 4.3.6 - 4.4.4 - Plugin Backdoor
2017-12-19 00:00
Matt BarryStrategic Overview
Vulnerability Overview
The Captcha plugin for WordPress contained a backdoor that injected SEO spam into unsuspecting users WordPress sites in version 4.3.6 to 4.4.4.
Technical Analysis
REMEDIATION: Update to version 4.4.5, or a newer patched version --- IDENTIFIER: CWE-912 (Hidden Functionality) The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C