CVE-2026-1369: Unknown Conditional Captcha

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Affected products

  • Unknown Conditional Captcha: up to and including 4.0.0

Published 2026-02-22. Last modified 2026-06-17.