Description

WordPress Plugin Captcha contains a backdoor. Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Captcha versions starting from 4.3.6 and up to, and including 4.4.4 are vulnerable.

Remediation

Update to plugin version 4.4.5 or latest

References

Related Vulnerabilities