Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4121

18
FAUCET Score

OVERVIEW CVE-2026-4121 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Kcaptcha plugin for WordPress in all versions up to and including 1.0.1. The plugin fails to implement proper nonce validation in its settings page handler, allowing unauthenticated attackers to forge requests that modify CAPTCHA configuration settings, including the ability to enable or disable CAPTCHA protection on login, registration, lost password, and comment forms. SEVERITY This vulnerability presents a network-based attack vector requiring no authentication but necessitating user interaction (social engineering). The attack complexity is low, with attackers needing only to trick a site administrator into clicking a malicious link. The impact is limited to integrity violations, as attackers can alter plugin settings but cannot access sensitive data or disrupt availability. The CVSS 3.1 base score of 4.3 (MEDIUM) reflects this limited but meaningful risk. EXPLOITATION STATUS The vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no indication of active exploitation in the wild, with an extremely low EPSS score of 0.000060000. Community attention appears minimal, as evidenced by the inactive Hot List status. However, the straightforward nature of CSRF attacks and the availability of the vulnerability details suggest that exploitation proof-of-concept code could be readily developed if threat actors choose to target this plugin.

Impacted Technologies

VendorProductVersion(s)CPE
KsolvesKcaptcha
>= 0, <= 1.0.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 6th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/kcaptcha/tags/1.0.1/admin/setting.php
plugins.trac.wordpress.org / browser/kcaptcha/tags/1.0.1/admin/setting.php
plugins.trac.wordpress.org / browser/kcaptcha/tags/1.0.1/admin/setting.php
plugins.trac.wordpress.org / browser/kcaptcha/trunk/admin/setting.php
plugins.trac.wordpress.org / browser/kcaptcha/trunk/admin/setting.php
plugins.trac.wordpress.org / browser/kcaptcha/trunk/admin/setting.php
wordfence.com / threat-intel/vulnerabilities/id/a6c1c73b-76e3-4cb9-ad53-9d5d4e7519c9