
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1075 is a Cross-Site Request Forgery (CSRF) vulnerability in the ZT Captcha plugin for WordPress, affecting all versions up to and including 1.0.4. The flaw allows unauthenticated attackers to modify plugin settings by tricking a site administrator into clicking a malicious link. It was reported by Wordfence and published on January 24, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, RedHat CVE).
The root cause is improper nonce validation (CWE-352) in the save_ztcpt_captcha_settings action handler within CaptchaRequest.php (line 37). Specifically, the nonce check can be bypassed by submitting an empty token value, effectively nullifying WordPress's built-in CSRF protection mechanism. An attacker crafts a forged HTTP request targeting this action and socially engineers a logged-in administrator to trigger it — for example, by embedding the request in a malicious webpage or link. No authentication is required on the attacker's side; only the victim's authenticated session is needed (Wordfence, ZT Captcha Source).
Successful exploitation allows an attacker to modify the ZT Captcha plugin's settings on the affected WordPress site, potentially disabling or misconfiguring CAPTCHA protections. This could expose the site to automated spam, brute-force login attempts, or bot-driven form abuse that the CAPTCHA was intended to prevent. The impact is limited to integrity (no confidentiality or availability impact), and exploitation is constrained to the plugin's configuration scope without direct code execution or data exfiltration (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1075. The EPSS score is approximately 0.02%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering of a site administrator, which raises the practical bar for attackers (Feedly).
save_ztcpt_captcha_settings action with an empty nonce value (e.g., nonce=) and desired malicious plugin settings as POST parameters.action=save_ztcpt_captcha_settings parameter and an empty or missing nonce field.Users should update the ZT Captcha plugin to a version beyond 1.0.4 that includes a proper nonce validation fix. Until a patched version is available, administrators should consider deactivating the plugin or restricting access to the WordPress admin area via IP allowlisting. General hardening measures include training administrators to avoid clicking unsolicited links while logged into WordPress, and enabling a web application firewall (WAF) such as Wordfence to detect and block CSRF attempts (Wordfence).
The vulnerability was discovered and disclosed by Wordfence, which published the advisory on January 24, 2026. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence disclosure has been identified. The CVE record is noted as not being prioritized for NVD enrichment due to resource constraints (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."