CVE-2026-103347
hCaptcha for WP に報告された脆弱性
概要
The hCaptcha for WP plugin for WordPress is vulnerable to Bypass Vulnerability in all versions up to, and including, 5.3.0. This is due to form action registrations stored exclusively in a WordPress transient that could expire or be evicted, causing get_registered_form() to return null and skip the hCaptcha requirement for auto-verified forms. This makes it possible for unauthenticated attackers to bypass hCaptcha verification on auto-verified forms by waiting for or triggering transient expiration, causing the plugin to skip the captcha check entirely. The site must use AutoVerify (auto-detected hCaptcha integration) for at least one form.
影響を受けるバージョン
- 5.3.0 以下
対処方法
hCaptcha for WP を 5.4.0 以降に更新してください。これで本脆弱性は解消します。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する