Description
WordPress Plugin Captcha contains a backdoor. Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Captcha versions starting from 4.3.6 and up to, and including 4.4.4 are vulnerable.
Remediation
Update to plugin version 4.4.5 or latest
References
https://www.wordfence.com/blog/2017/12/backdoor-captcha-plugin/
Related Vulnerabilities
MySQL CVE-2015-4819 Vulnerability (CVE-2015-4819)
Apache HTTP Server Other Vulnerability (CVE-2002-1592)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.25)
WordPress Plugin WP Users Exporter CSV Injection (1.4.2)
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2016-9451)