AI Search
Classic Search
 Search Phrase:
 Search Type:
Advanced search options
 Search in Forums:
 Search in date period:

 Sort Search Results by:

AI Assistant
Notifications
Clear all

[Closed] Recaptcha bug

2 Posts
2 Users
1 Reactions
1,793 Views
Posts: 23
Topic starter
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@mistral)
Eminent Member
Joined: 7 years ago
[#8139]

Hi Guys

I have found a fairly serious issue with the implementation of the recaptcha for the 'registration' process. Login and password reset do not seem to be affected. I don't know about other instances.

https://wpforo.com/community/?wpforo=signup

If you try to register with an existing username and do not check the recaptcha, you will still receive an error that the user already exists and the email is in use. 

This defeats the purpose of recaptcha to protect the form, as the ONLY response from the form when the recaptcha is missing, should be that there is a recaptcha error. Currently it would be possible to brute force checking usernames and emails regardless of there being the recaptcha.

I'm hoping this can be fixed without too much effort.

Regards

Mistral


1 Reply
Robert
Posts: 10736
Admin
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@robert)
Support Team
Joined: 2 months ago

Good point. The reCAPTCHA we'll take a look on this.


Share: