reCaptcha should be checked before username validation

[ad_1]

Hello!
I tried using this plugin for my website, tested it on the login page, and I found out that the reCaptcha validation occurs after the username validation. This way anyone (even bots) can try guessing usernames without having to deal with the captcha – and if it hits a reCaptcha error, it means that it just found a valid username. I think it would make a site more secure to validate the captcha before all the user related validations. Maybe try using the “authenticate” filter instead of “wp_authenticate_user”.

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer