Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scripting via 'action' Parameter
high
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...
- CVSS:
- 7.2
- Affected:
- up to 5.1
- Fixed in:
- 5.1.1
- Disclosed:
- Aug 14, 2026
CVE-2026-16145 on NVD →
Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values
medium
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu...
- CVSS:
- 4.9
- Affected:
- up to 5.1
- Fixed in:
- 5.1.1
- Disclosed:
- Aug 14, 2026
CVE-2026-16146 on NVD →
Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via 'key' Parameter
medium
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....
- CVSS:
- 4.9
- Affected:
- up to 5.1
- Fixed in:
- 5.1.1
- Disclosed:
- Aug 14, 2026
CVE-2026-16094 on NVD →
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant <= 4.1.1 - Cross-Site Request Forgery
medium
The Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an...
- CVSS:
- 4.3
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Jun 5, 2025
CVE-2025-49283 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database