Impact
The vulnerability is a CSRF flaw (CWE‑352) that allows attackers to perform actions on behalf of an authenticated user who is visiting a malicious site that tricks the user into sending a request to the compromised WordPress installation. The impact is the potential alteration of site configuration, submission of unwanted data, or other state‑changing operations without the user’s consent. It does not directly expose data or allow code execution, but it can lead to broader attacks if the actions performed can be exploited further.
Affected Systems
All installations of Brian S. Reed’s Contact Form 7 reCAPTCHA plugin up to, and including, version 1.2.0. The plugin is typically deployed on WordPress sites that already have the Contact Form 7 plugin installed.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low to moderate severity. The EPSS score of < 1% indicates a very low exploitation probability. It is not listed in CISA’s KEV catalog. The most likely attack vector is a CSRF request sent from an attacker’s site to a target that has an authenticated user with sufficient privileges. Attacking requires that the target user is online and has an active session with the WordPress site. No additional conditions or privileged access are explicitly required by the description.
OpenCVE Enrichment
EUVD