Recaptcha v2 – enumeration vulnerability – password recovery form
-
Dear Sir or Madam,
I have noticed an enumeration vulnerability (found by a vulnerability scan).
The ReCaptchaV2 does not work as it should on the password recovery page /wp-login.php?action=lostpassword
When you try to recover a password with a non-existing user the ReCaptcha does not trigger. WordPress just says wrong username and password. So when someone tries to recover a password with a non-existing user the captcha is bypassed.
So, in theory, someone could use this to find out the username.
Next to that the tool also found that the server does not validate the CAPTCHA response parameter <— if this is due to our server or a bug in the plugin was not clear.
Looking forward to your thoughts.
Regards,
The page I need help with: [log in to see the link]
- The topic ‘Recaptcha v2 – enumeration vulnerability – password recovery form’ is closed to new replies.