Impact
The vulnerability is an Improper Neutralization of Input during web page generation that permits reflected XSS in the Are you robot google recaptcha for wordpress plugin. A malicious user can embed script code in a specially crafted request that the plugin will include unchecked in the response, enabling arbitrary script execution in the victim’s browser. This can lead to session hijacking, cookie theft, or defacement of the site, exposing confidential data and compromising the integrity of web pages.
Affected Systems
The issue impacts the Are you robot google recaptcha for wordpress plugin from the earliest public release up through version 2.2, all managed by the sureshdsk vendor. No specific patch or newer version is listed in the data, indicating that all releases up to 2.2 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. With an EPSS score below 1 % the probability of exploitation at any given time is low, and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, attackers can trigger the reflected XSS simply by delivering a crafted URL or form input to a user who has the plugin enabled, so the risk is still significant for multi‑tenant WordPress installations that expose the vulnerable plugin to public input.
OpenCVE Enrichment
EUVD