Summary
CVE-2026-65556 is an unauthenticated PHP Object Injection vulnerability in the WPBruiser {no-Captcha anti-Spam} WordPress plugin (package goodbye-captcha) by MihChe, affecting all versions up to and including 3.1.43. The flaw stems from deserialization of untrusted data (CWE-502) and carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: Deserialization of untrusted data (CWE-502), allowing PHP Object Injection.
- Trigger conditions: Exploitable by an unauthenticated attacker with no user interaction and low attack complexity.
- Attack vector: Network — remotely exploitable over HTTP/HTTPS.
- Impact: High impact to confidentiality, integrity, and availability, enabling full compromise of the affected system.
Affected software
- WPBruiser {no-Captcha anti-Spam} (
goodbye-captcha) by MihChe — versions up to and including 3.1.43.
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector string:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Update WPBruiser {no-Captcha anti-Spam} to a version later than 3.1.43 once released by the vendor.
- If no patch is available: Restrict or deactivate the plugin until a fixed release is deployed, and place the site behind a WAF to filter untrusted serialized payloads and requests targeting the plugin’s endpoints.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw HTTP response body:
/wp-content/plugins/goodbye-captcha/

