5.8

CVE-2025-8280

Exploit

Contact Form 7 reCAPTCHA <= 1.2.0 - Reflected XSS via $_SERVER['REQUEST_URI']

Contact Form 7 reCAPTCHA <= 1.2.0 - Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI']

The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.
Mögliche Gegenmaßnahme
Contact Form 7 reCAPTCHA: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IambriansreedContact Form 7 Recaptcha SwPlatformwordpress Version <= 1.2.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Contact Form 7 reCAPTCHA
Version *-1.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.085
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.8 1.6 3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/f8370026-6293-4814-961f-c254ee8e844d/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/00c7b97b-4c5e-436a-967e-007ee1d283fb
Third Party Advisory