CVE-2014-9283
UnknownEPSS 2.35%
Last modified
CVE-2014-9283 is a vulnerability of currently unknown severity. The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.. EPSS estimates a 2.35% chance of exploitation in the next 30 days.
Description
The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bestwebsoft | Captcha | <= 4.0.6 |
References
- http://jvn.jp/en/jp/JVN93727681/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000029Vendor Advisory
- http://jvn.jp/en/jp/JVN93727681/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000029Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-9283?
The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.
How severe is CVE-2014-9283?
Severity scoring for CVE-2014-9283 is pending analysis. The EPSS model estimates a 2.35% probability of exploitation in the next 30 days.
How do I fix CVE-2014-9283?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-9277The wfMangleFlashPolicy function in OutputHandler.php in Med…
- CVE-2014-9278The OpenSSH server, as used in Fedora and Red Hat Enterprise…
- CVE-2014-9279The print_test_result function in admin/upgrade_unattended.p…
- CVE-2014-9280The current_user_get_bug_filter function in core/current_use…
- CVE-2014-9281Cross-site scripting (XSS) vulnerability in admin/copy_field…
- CVE-2014-9282Directory traversal vulnerability in the Speed Root Explorer…
- CVE-2014-9284The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 an…
- CVE-2014-9285Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-9286Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-9287Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-9288Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-9289Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2014-9283?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
