plugin

Gdpr Compliant Recaptcha For All Forms Vulnerabilities

4 known security issues reported for the Gdpr Compliant Recaptcha For All Forms WordPress plugin. Most recent disclosed Aug 14, 2026.

1 high 3 medium

Running Gdpr Compliant Recaptcha For All Forms on your site? Check whether your installed version is affected.

Scan your site free

Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scripting via 'action' Parameter

high

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

CVSS:
7.2
Affected:
up to 5.1
Fixed in:
5.1.1
Disclosed:
Aug 14, 2026

CVE-2026-16145 on NVD →

Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values

medium

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu...

CVSS:
4.9
Affected:
up to 5.1
Fixed in:
5.1.1
Disclosed:
Aug 14, 2026

CVE-2026-16146 on NVD →

Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via 'key' Parameter

medium

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

CVSS:
4.9
Affected:
up to 5.1
Fixed in:
5.1.1
Disclosed:
Aug 14, 2026

CVE-2026-16094 on NVD →

Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant <= 4.1.1 - Cross-Site Request Forgery

medium

The Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an...

CVSS:
4.3
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Jun 5, 2025

CVE-2025-49283 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database