CVE-2011-10033
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedThe WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter is set to 'log-reset'. The root cause is unsafe use of eval() on user-controlled input, which can lead to execution of attacker-supplied PHP and OS commands. This may result in arbitrary code execution as the webserver user, site compromise, or data exfiltration. The is-human plugin was made defunct in June 2008 and is no longer available for download. This vulnerability was exploited in the wild in March 2012. Source description excerpt; complete tracked detail loads below.
NVD published: Oct 15, 2025 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What is affected
Reportedberlette — is-human WordPress Plugin. Product-level identification only; no affected-version conclusion is available from this field.
NVD published: Oct 15, 2025 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Urgency and basis
ReportedAct · 446.0
Tracker decision tier from the evidence detailed below · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Exploitation evidence
Reportedkev-listed · VulnCheck KEV
VulnCheck KEV added: Mar 12, 2012 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What to do
ReportedApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Tracked source remediation field · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Evidence detail
Loading the full tracker evidence record…