plugin

Contact Form 7 Simple Recaptcha Vulnerabilities

4 known security issues reported for the Contact Form 7 Simple Recaptcha WordPress plugin. Most recent disclosed Jul 17, 2022.

1 high 1 medium

Running Contact Form 7 Simple Recaptcha on your site? Check whether your installed version is affected.

Scan your site free

Contact Form 7 Captcha [contact-form-7-simple-recaptcha] < 0.1.2

unknown

[en] The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

Affected:
up to 0.1.2
Fixed in:
0.1.2
Disclosed:
Jul 17, 2022

CVE-2022-2187 on NVD →

Contact Form 7 Captcha <= 0.1.1 - Reflected Cross-Site Scripting

medium

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVSS:
6.1
Affected:
up to 0.1.1
Fixed in:
0.1.2
Disclosed:
Jun 27, 2022

CVE-2022-2187 on NVD →

Contact Form 7 Captcha [contact-form-7-simple-recaptcha] < 0.0.9

unknown

[en] The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issu...

Affected:
up to 0.0.9
Fixed in:
0.0.9
Disclosed:
Aug 23, 2021

CVE-2021-24565 on NVD →

Contact Form 7 Captcha <= 0.0.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.

CVSS:
8.8
Affected:
up to 0.0.9
Fixed in:
0.0.9
Disclosed:
Jul 26, 2021

CVE-2021-24565 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database