CVE-2026-1369 PUBLISHED

Conditional CAPTCHA <= 4.0.0 - Open Redirect

Assigner: WPScan
Reserved: 23.01.2026 Published: 22.02.2026 Updated: 22.02.2026

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Product Status

Vendor Unknown
Product Conditional CAPTCHA
Versions Default: affected
  • affected from 0 to 4.0.0 (incl.)

Credits

  • Bob Matyas finder
  • WPScan coordinator

References

Problem Types

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect') CWE