CVE-2026-97317
Received Received - Intake

RafflePress reCAPTCHA Secret Key Exposure Vulnerability

Vulnerability report for CVE-2026-97317, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rafflepress giveaways_and_contests to 1.12.27 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in the Giveaways and Contests by RafflePress WordPress plugin before version 1.12.27 allows unauthenticated visitors to retrieve the reCAPTCHA secret key from public giveaway pages. This occurs because the plugin does not remove the secret key from embedded settings on these pages.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Giveaways and Contests by RafflePress plugin version prior to 1.12.27. Inspect public giveaway pages for exposed reCAPTCHA secret keys in embedded settings. Use commands like 'curl' to fetch page source and search for 'recaptcha' or 'secret key' patterns.

Impact Analysis

This vulnerability can lead to sensitive data exposure, specifically the reCAPTCHA secret key, which could be exploited by attackers to bypass reCAPTCHA protections on websites using the plugin.

Mitigation Strategies

Immediately update the Giveaways and Contests by RafflePress plugin to version 1.12.27 or later. Review and remove any exposed reCAPTCHA secret keys from public giveaway pages. Monitor for unauthorized access or suspicious activity related to reCAPTCHA keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97317. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart