Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rafflepress
Rafflepress giveaways And Contests By Rafflepress Wordpress-extensions Wordpress-extensions giveaways And Contests By Rafflepress |
|
| Vendors & Products |
Rafflepress
Rafflepress giveaways And Contests By Rafflepress Wordpress-extensions Wordpress-extensions giveaways And Contests By Rafflepress |
Fri, 02 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 02 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Fri, 02 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured. | |
| Title | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-02T10:54:11.320Z
Reserved: 2026-09-24T11:27:48.588Z
Link: CVE-2026-97317
Updated: 2026-10-02T10:43:56.084Z
Status : Received
Published: 2026-10-02T06:16:43.693
Modified: 2026-10-02T11:17:39.423
Link: CVE-2026-97317
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:46:27Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor