Impact
The Captcha.eu WordPress plugin contains a reflected XSS flaw due to improper neutralization of input during web page generation. The plugin echoes user‑supplied parameters directly into a page without sanitization, creating an opportunity for reflected cross‑site scripting.
Affected Systems
WordPress sites that have installed the Captcha.eu plugin from vendor captcha.eu and are running any version earlier than 1.0.61 are vulnerable. The flaw is present in all releases prior to 1.0.61.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk, while the EPSS score of less than 1 % indicates a low current probability of exploitation. The flaw is a reflected XSS that can be triggered via a crafted URL or malicious link, requiring no authentication or elevated privileges. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
EUVD