Captchinoo, admin login page protection with Google recaptcha
Captchinoo, admin login page protection with Google recaptcha has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2021; all 2 are fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2021 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Improper Authorization.
Every one of the 2 issues recorded for Captchinoo, admin login page protection with Google recaptcha has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Captchinoo, admin login page protection with Google recaptcha is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
Captchinoo, admin login page protection with Google recaptcha <= 2.4 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
Read the full analysisVulnerability Records

Captchinoo, admin login page protection with Google recaptcha
Author
wp-buy
Your login page is the single most attacked page on any WordPress site. Bots hit wp-login.php around the clock, guessing username and password combinations thousands of times a day. Captchinoo puts a human verification step in front of that form, so automated scripts are stopped before they ever reach your password check. Install it, pick the captcha style you like, and you are protected. There is nothing else to configure. Three captcha styles, one click apart Slide to unlock — a lightweight swipe slider, just like unlocking a phone. No external service, no API keys, works on desktop and touch devices. Icon captcha — the visitor picks the one icon that does not belong in the row. Friendly, image based, and no typing required. Google reCAPTCHA v2 — the familiar “I’m not a robot” checkbox, backed by Google’s own bot detection. Why site owners choose Captchinoo No puzzles to read. No distorted letters and no math questions. Your users are not punished for logging in. Genuinely lightweight. Only the assets for the captcha you actually selected are loaded, and only on the login page. Nothing is queued on the front end of your site. Works with caching. The login page is never cached by page caching plugins, so Captchinoo stays reliable where other captcha plugins break. Translation ready. Every string is translatable and the plugin ships with full text domain support. Zero configuration required. The slide captcha works the moment you activate the plugin — no account, no keys, no signup. Captchinoo Pro — three more ways to lock down your login The free plugin gives you three captcha styles for your WordPress login form. Captchinoo Pro adds three stronger layers on top: Two factor authentication (2FA) — the most powerful protection in the plugin. 2FA adds a second identity check on top of the password: the user confirms the login from their mobile device, so a stolen, leaked, or guessed password on its own is no longer enough to get into your site. Google reCAPTCHA v3 — invisible protection that never interrupts your users. Instead of asking anyone to click a box or solve a challenge, reCAPTCHA v3 scores each visitor silently in the background from their interactions with your site. You can run it everywhere without affecting your conversion rate, and it works best when it has the most context about how people use your site. hCaptcha — an independent alternative to Google’s service. hCaptcha blocks automated bots, spam, and abuse by asking visitors to complete a simple verification challenge, and it is the popular choice for site owners who would rather not route their traffic through Google. Pro includes everything in the free version, so you can switch between all six captcha styles at any time. External services This plugin can optionally use Google reCAPTCHA, a third party service, and only when you explicitly select “Google reCAPTCHA” as your captcha type and enter your own API keys. When that option is active, the visitor’s browser loads Google’s reCAPTCHA script from https://www.google.com/recaptcha/api.js, and your server sends the captcha response token together with the visitor’s IP address to https://www.google.com/recaptcha/api/siteverify in order to confirm the challenge was solved. No data is transmitted to Google when the Slide or Icon captcha is selected, and the plugin never sends data anywhere else. Google’s terms and privacy policy apply to that service: Terms of Service — Privacy Policy. Support If you have a problem, a question, or a feature request, please open a thread in the support forum. We answer every one. If Captchinoo helps keep your site safe, a review would mean a lot to us.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C