Sceawere
Vulnerability Detail
CVE-2026-39772UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Captcha by BestWebSoft Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 16h ago
- Vendor
- bestwebsoft
- Product
- Captcha by BestWebSoft
- Attack Type
- CWE-290 Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-06T09:17:49.740Z",
"pubdate": "2026-10-06T09:17:49.740Z",
"executiveSummary": "The Captcha by BestWebSoft plugin, in versions 5.2.8 and earlier, is susceptible to an unauthenticated security bypass vulnerability.\nThis flaw allows remote, unauthenticated attackers to circumvent the CAPTCHA protection mechanism implemented by the plugin.\nThe vulnerability type is an authentication/validation bypass, which invalidates the security posture of protected forms, such as login pages, comment sections, or registration forms.\nSuccessful exploitation permits attackers to submit form data without completing the required challenge-response interaction.\nThis potentially facilitates automated abuse, including brute-force attacks on authentication interfaces, spam injection, or the automated creation of unauthorized accounts.\nThe risk implication is high, as it renders the primary security function of the plugin ineffective, exposing the host application to a variety of automated threats.",
"technicalDetails": "The vulnerability resides within the validation logic of the Captcha by BestWebSoft plugin. The root cause is a failure to properly verify the CAPTCHA response state during form submission processes.\nIn affected versions (<= 5.2.8), the plugin fails to strictly enforce server-side validation of the CAPTCHA token or user-provided response, allowing the submission process to proceed even when the CAPTCHA is invalid, missing, or bypassed entirely by the client.\nThe attack flow typically involves an unauthenticated actor targeting a protected form (e.g., wp-login.php, comment forms, or contact forms). Instead of solving the CAPTCHA, the attacker manipulates the request, either by omitting the CAPTCHA-related POST parameters or by submitting malformed/static data that the backend logic incorrectly interprets as a successful validation.\nBecause the plugin logic does not adequately verify the integrity or session-association of the CAPTCHA challenge before allowing the underlying form processing to trigger, the backend application assumes the interaction is legitimate.\nThis vulnerability is critical because it bypasses the intent of the security control. If the plugin is used to secure a login form, an attacker can bypass the CAPTCHA to automate dictionary or brute-force attacks on user credentials, significantly increasing the success rate of account takeovers.\nIf used on contact or comment forms, it allows for the mass dissemination of spam content, defeating the rate-limiting and anti-bot protections provided by the plugin.\nThe vulnerability is accessible over the network without any requirement for authentication or specific privileges, making it highly attractive for automated botnet operations.\nPost-exploitation, the attacker maintains the ability to interact with the target form's application logic as if they were a validated, legitimate user, bypassing the intended gatekeeping mechanism."
}