---
id: CVE-2026-97317
title: >-
  The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27
  does not remove the reCAPTCHA secret key from the giveaway settings it embeds
  in public giveaway pages, allowing unauthenticated visitors to retrieve the
  secret k…
summary: >-
  The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27
  does not remove the reCAPTCHA secret key from the giveaway settings it embeds
  in public giveaway pages, allowing unauthenticated visitors to retrieve the
  secret k…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Giveaways and Contests by RafflePress
affected:
  - giveaways_and_contests_by_rafflepress < 1.12.27
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:00:34.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97317'
references:
  - url: 'https://wpscan.com/vulnerability/f8779fd4-f362-40c4-8df1-145620c69103/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00139
epssPercentile: 0.02758
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-02T10:45:09.487670Z'
ingestedAt: '2026-10-02T06:11:20.482Z'
---

## Overview

The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
