Skip to content

CVE-2026-10552

Cross-Site Request Forgery (CSRF): is CVE-2026-10552real, exploitable, or a false positive? Here's the community verdict.

Medium · CVSS 4.3EPSS 0.1%CWE-352 · Cross-Site Request Forgery (CSRF)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap_main_page) and on the Hall of Shame and Log subpages, which accept a 'blcap_action' / 'action' parameter from $_REQUEST and perform destructive operations (plugin uninstall via blcap_uninstall(), log deletion via blcap_delete_logs(), Hall of Shame deletion via blcap_delete_ip_db(), and adding IPs to the banned list via update_option('blcap_settings')) with no wp_verify_nonce(), check_admin_referer(), or check_ajax_referer() calls anywhere in the codebase. This makes it possible for unauthenticated attackers to uninstall the plugin, delete audit logs, remove Hall of Shame entries, and add arbitrary IP addresses to the block list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Published

Embed this verdict
TruePositive verdict for CVE-2026-10552
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2026-10552/badge.svg)](https://www.truepositive.app/cve/CVE-2026-10552)
HTML
<a href="https://www.truepositive.app/cve/CVE-2026-10552"><img src="https://www.truepositive.app/cve/CVE-2026-10552/badge.svg" alt="TruePositive verdict for CVE-2026-10552"></a>

Live badge that updates automatically as the community verdict changes.

Community ground truth

In your experience, is this finding real and exploitable?

0 verdicts
Not a real issue

No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.

Field notes & remediation

Verdicts are the quick signal. Notes are the evidence and fixes behind them.

No notes yet. Be the first to share what you saw, or a fix that worked.

    Add a field note or remediationoptional
    Note type

    What are you adding?

    Markdown supported · minimum 20 characters.

    Same weakness: CWE-352 · Cross-Site Request Forgery (CSRF).