CVE-2026-5415 is an authentication bypass vulnerability affecting WP Captcha PRO, the premium version of the Advanced Google reCAPTCHA WordPress plugin, in versions up to and including 5.38. The flaw is caused by a chain of authorization weaknesses in the plugin’s temporary login link functionality. The ajax_run_tool() AJAX handler relies on a nonce check through check_ajax_referer() but does not enforce a capability check to ensure the caller is authorized to invoke privileged tools. Under the condition that the plugin’s welcome pointer has not been dismissed, the required nonce is exposed to authenticated backend users, including Subscribers, via wp_localize_script() on non-settings admin pages. An authenticated low-privilege user can use that nonce to invoke the create_temporary_link tool for an arbitrary target account. The resulting passwordless login link is then accepted by handle_temporary_links(), which authenticates the visitor without additional authorization validation. This allows a low-privilege authenticated user to bypass normal authentication controls and assume the identity of any account on the site, including Administrators.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script and a minimal README. The main file, CVE-2026-5415.py, is a standalone authenticated web exploit targeting CVE-2026-5415 in the WordPress WP Captcha PRO plugin. The script uses requests.Session for stateful HTTP interaction and is structured around a WPCaptchaExploit class with helper methods for login, nonce extraction from authenticated wp-admin pages, AJAX action discovery, user enumeration, and full account-takeover exploitation. It authenticates with subscriber credentials at /wp-login.php, scrapes multiple admin pages for exposed nonces created via wp_localize_script(), searches page source for plugin-specific AJAX action names related to recaptcha/captcha functionality, and then abuses the vulnerable temporary-login-link workflow through WordPress AJAX handling to impersonate an arbitrary target user. Command-line options support full exploitation as well as separate reconnaissance modes: --enumerate, --find-action, and --find-nonce. Overall, this is a real operational exploit rather than a detector: it requires valid low-privileged credentials and returns unauthorized access to another account, potentially an administrator.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A companion high-severity authentication bypass vulnerability in WP Captcha PRO via temporary login link, disclosed alongside CVE-2026-5411.
An authentication bypass vulnerability in WP Captcha PRO that lets a low-privileged authenticated user generate passwordless login links for arbitrary accounts, including administrators, leading to full site takeover.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.