CVE-2026-5411: CWE-434 Unrestricted Upload of File with Dangerous Type in webfactory Advanced Google reCAPTCHA
The WP Captcha PRO plugin (premium version of Advanced Google reCAPTCHA) for WordPress has a vulnerability allowing authenticated users with Subscriber-level access or higher to upload arbitrary files, including PHP webshells. This occurs due to insufficient file type validation during a file extraction process triggered by a malicious URL in the license meta. Exploitation requires the PHP configuration option allow_url_fopen to be enabled. Versions up to and including 5.38 are affected. This vulnerability can lead to remote code execution on the server.
AI Analysis
Technical Summary
CVE-2026-5411 is a vulnerability in the WP Captcha PRO plugin (Advanced Google reCAPTCHA) for WordPress, affecting all versions up to 5.38. The issue arises from a capability check flaw in the save_ajax() licensing function combined with unrestricted file extraction in sync_cloud_protection(). Authenticated attackers with Subscriber-level privileges can inject a malicious cloud_protection_url into the license meta, causing the plugin to download and extract arbitrary files without validating file types into a web-accessible uploads directory. If PHP's allow_url_fopen is enabled, this can be exploited remotely to upload PHP webshells, enabling remote code execution.
Potential Impact
An attacker with at least Subscriber-level access can upload arbitrary files, including executable PHP webshells, to the server. This can lead to full remote code execution, compromising confidentiality, integrity, and availability of the affected system. The vulnerability requires allow_url_fopen to be enabled for remote URL exploitation. The CVSS v3.1 score is 8.8, indicating high severity with network attack vector, low attack complexity, and no user interaction required.
Mitigation Recommendations
No official patch or fix has been confirmed as of the published date. Users should check the vendor advisory for updates. Until a fix is available, consider disabling allow_url_fopen in php.ini to prevent remote URL exploitation. Restricting plugin access to trusted users and monitoring for suspicious uploads may reduce risk. Avoid using versions up to and including 5.38 where possible.
CVE-2026-5411: CWE-434 Unrestricted Upload of File with Dangerous Type in webfactory Advanced Google reCAPTCHA
Description
The WP Captcha PRO plugin (premium version of Advanced Google reCAPTCHA) for WordPress has a vulnerability allowing authenticated users with Subscriber-level access or higher to upload arbitrary files, including PHP webshells. This occurs due to insufficient file type validation during a file extraction process triggered by a malicious URL in the license meta. Exploitation requires the PHP configuration option allow_url_fopen to be enabled. Versions up to and including 5.38 are affected. This vulnerability can lead to remote code execution on the server.
CVSS v3.1
Score 8.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-5411 is a vulnerability in the WP Captcha PRO plugin (Advanced Google reCAPTCHA) for WordPress, affecting all versions up to 5.38. The issue arises from a capability check flaw in the save_ajax() licensing function combined with unrestricted file extraction in sync_cloud_protection(). Authenticated attackers with Subscriber-level privileges can inject a malicious cloud_protection_url into the license meta, causing the plugin to download and extract arbitrary files without validating file types into a web-accessible uploads directory. If PHP's allow_url_fopen is enabled, this can be exploited remotely to upload PHP webshells, enabling remote code execution.
Potential Impact
An attacker with at least Subscriber-level access can upload arbitrary files, including executable PHP webshells, to the server. This can lead to full remote code execution, compromising confidentiality, integrity, and availability of the affected system. The vulnerability requires allow_url_fopen to be enabled for remote URL exploitation. The CVSS v3.1 score is 8.8, indicating high severity with network attack vector, low attack complexity, and no user interaction required.
Mitigation Recommendations
No official patch or fix has been confirmed as of the published date. Users should check the vendor advisory for updates. Until a fix is available, consider disabling allow_url_fopen in php.ini to prevent remote URL exploitation. Restricting plugin access to trusted users and monitoring for suspicious uploads may reduce risk. Avoid using versions up to and including 5.38 where possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-04-02T07:07:02.783Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a231d8ee29bf47b50a9841b
Added to database: 06/05/2026, 19:03:42 UTC
Last enriched: 06/13/2026, 09:55:33 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.