An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and password-recovery form require solving a CAPTCHA to perform actions. However, this is required only once per user session, and therefore one could send as many requests as one wished by automation.
References
Link | Resource |
---|---|
https://github.com/aas-n/CVE/tree/master/ajax-bootmodal-login | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-08-26 07:29
Updated : 2024-02-04 20:03
NVD link : CVE-2018-15876
Mitre link : CVE-2018-15876
CVE.ORG link : CVE-2018-15876
JSON object : View
Products Affected
ajax_bootmodal_login_project
- ajax_bootmodal_login
CWE
CWE-20
Improper Input Validation