Description
The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32508 | The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack. |
References
History
Mon, 05 May 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bozdoz
Bozdoz recaptcha Jetpack |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:bozdoz:recaptcha_jetpack:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Bozdoz
Bozdoz recaptcha Jetpack |
Fri, 28 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-28T19:17:28.423Z
Reserved: 2024-04-17T22:00:18.630Z
Link: CVE-2024-3941
Updated: 2024-08-01T20:26:57.170Z
Status : Analyzed
Published: 2024-05-14T15:42:36.890
Modified: 2025-05-05T17:06:46.290
Link: CVE-2024-3941
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD