Impact
The WP‑NOTCAPTCHA WordPress plugin contains an improper neutralization of input during web page generation that permits reflected cross-site scripting. An attacker can supply crafted input that is echoed back into the page without proper escaping, allowing arbitrary script code to execute in the victim’s browser.
Affected Systems
WordPress sites that have the webjema WP‑NOTCAPTCHA plugin installed in version 1.3.1 or earlier are affected. No additional product or version ranges are specified.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity. The EPSS score of less than 1 % and absence from CISA’s KEV catalog indicate that large‑scale exploitation is unlikely at present. The vulnerability involves reflected user input; an attacker can exploit it by directing a victim to a URL containing malicious payloads processed by the plugin, resulting in script execution within the victim’s browser.
OpenCVE Enrichment
EUVD