Description
WordPress Plugin Captcha contains a backdoor. Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Captcha versions starting from 4.3.6 and up to, and including 4.4.4 are vulnerable.
Remediation
Update to plugin version 4.4.5 or latest
References
https://www.wordfence.com/blog/2017/12/backdoor-captcha-plugin/
Related Vulnerabilities
WordPress Plugin Facebook for WordPress Cross-Site Request Forgery (3.0.3)
WordPress Plugin DirectoryPress-Business Directory And Classified Ad Listing SQL Injection (3.6.10)
MySQL CVE-2023-22015 Vulnerability (CVE-2023-22015)
WordPress Plugin Adsense Extreme 'adsensextreme[lang]' Parameter Remote File Include (1.0.3)