Sceawere

Vulnerability Detail

CVE-2026-97317UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RafflePress Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
17h ago
Vendor
Unknown
Product
Giveaways and Contests by RafflePress
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T06:16:43.693Z",
  "pubdate": "2026-10-02T06:16:43.693Z",
  "executiveSummary": "The Giveaways and Contests by RafflePress WordPress plugin, in versions prior to 1.12.27, is susceptible to an Information Disclosure vulnerability.\nThe flaw exists due to the improper handling of reCAPTCHA configuration data during the rendering of public-facing giveaway pages.\nAn unauthenticated, remote attacker can retrieve the reCAPTCHA secret key for any active giveaway configured with reCAPTCHA protection by inspecting the page source or network responses.\nExposure of a reCAPTCHA secret key compromises the integrity of the CAPTCHA validation process, as it allows attackers to bypass security checks or potentially conduct server-side forgery attacks against the reCAPTCHA API.\nThe risk implication is significant as the secret key serves as the primary authentication credential between the RafflePress server and Google's reCAPTCHA service. Successful exploitation requires no authentication or special privileges, making it easily accessible to any user capable of browsing the public website.",
  "technicalDetails": "The root cause of this vulnerability lies in the plugin's frontend rendering logic. When a giveaway is rendered on the public web interface, the server-side code transmits the giveaway settings object to the client-side JavaScript environment to facilitate interactive features.\nIn affected versions (pre-1.12.27), this settings object erroneously includes the reCAPTCHA secret key. Because this object is serialized directly into the HTML output—typically within a script block or a data attribute—it is exposed in the Document Object Model (DOM) of the rendered page.\nThe attack vector is passive and highly straightforward. An unauthenticated attacker navigates to any public URL where an active giveaway with reCAPTCHA is embedded. By viewing the page source code or utilizing browser developer tools (e.g., 'Inspect Element' or the Network tab), the attacker can search for the JSON-encoded configuration object. Upon locating the relevant JavaScript variable or configuration array, the attacker can extract the plaintext reCAPTCHA secret key associated with the site's Google reCAPTCHA account.\nBecause the secret key is intended to be kept private on the server side to verify the authenticity of user responses, its exposure to the client side violates the fundamental security model of the reCAPTCHA service. With the secret key, an attacker can potentially authenticate malicious requests as legitimate, successfully bypassing reCAPTCHA validation measures on the RafflePress installation.\nThe vulnerability affects all versions of the Giveaways and Contests by RafflePress plugin prior to 1.12.27. Exploitation is possible over the network without any requirement for user authentication or elevated privileges. Once the key is obtained, the post-exploitation impact includes the loss of anti-bot protections, enabling automated abuse, spam generation, or brute-force attempts on giveaway entry forms, as the attacker can sign or validate their own malicious tokens if the backend implementation relies solely on the key present in the client request."
}
CVE-2026-97317: RafflePress Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere