Description
WordPress Plugin Flexible Captcha is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass the captcha with a modified submission at login. WordPress Plugin Flexible Captcha version 4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.1 or latest
References
Related Vulnerabilities
Meteor Slides Cross-Site Scripting (1.5.6)
WordPress 4.5.x PHP Object Injection (4.5 - 4.5.23)
Joomla! Core 1.6.x Multiple Cross-Site Scripting Vulnerabilities (1.6.0 - 1.6.3)
Sina Extension for Elementor Local File Inclusion (2.2.0)
WordPress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (1.2.1 - 1.2.2)