Executive brief
The Login No Captcha reCAPTCHA plugin for WordPress, which adds security checkboxes to login pages to prevent automated bot attacks, is vulnerable to a security flaw. An attacker can inject malicious scripts into the website's administrative dashboard by making a specially crafted login request. If an administrator views the dashboard shortly after such an attack, the malicious script could execute in their browser, potentially allowing the attacker to perform unauthorized actions or compromise the site.
Technical details
The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient sanitization and escaping of the $_SERVER['PHP_SELF'] superglobal. The authenticate() function stores the unsanitized output of basename($_SERVER['PHP_SELF']) in the 'login_nocaptcha_error' WordPress option when a login attempt is made from a non-standard page like xmlrpc.php. Subsequently, the admin_notices() function echoes this stored value directly into the admin dashboard HTML without proper escaping. This allows unauthenticated attackers to inject arbitrary web scripts that execute when an administrator with a whitelisted IP address visits the dashboard within 30 seconds of the malicious request. The issue is fixed in version 1.8.1.
Affected products
- Robert Peake Login No Captcha reCAPTCHA up to, and including, 1.8.0
Timeline
- 2026-05-28: disclosed: CVE published to NVD
References
- https://plugins.trac.wordpress.org/browser/login-recaptcha/tags/1.7.3/login-nocaptcha.php
- https://plugins.trac.wordpress.org/browser/login-recaptcha/tags/1.7.3/login-nocaptcha.php
- https://plugins.trac.wordpress.org/browser/login-recaptcha/trunk/login-nocaptcha.php
- https://plugins.trac.wordpress.org/browser/login-recaptcha/trunk/login-nocaptcha.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3549342%40login-recaptcha&new=3549342%40login-recaptcha&sfp_email=&sfph_mail=
- https://wordpress.org/plugins/login-recaptcha/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/99dfce3b-2b47-41bf-8b20-b53fb9f061a7?source=cve