Impact
The Invisible Anti-Spam & CAPTCHA plugin for WordPress is vulnerable to a generic SQL Injection flaw in the 'key' parameter used by the plugin’s forms. The injection occurs because the value supplied by the user is not properly escaped or prepared within the SQL query. An attacker with sufficient privileges—specifically those on the Editor level or higher—can append malicious SQL fragments to the existing query. This can be used to retrieve, modify, or delete sensitive data stored in the WordPress database, thereby compromising data confidentiality and integrity.
Affected Systems
Any WordPress installation using the Invisible Anti-Spam & CAPTCHA – reCAPTCHA Alternative for All Forms plugin version 5.1 or earlier is affected. The plugin is delivered by the vendor matthiasnordwig. Precise version details are limited to the cutoff of 5.1; newer releases beyond 5.1 are not listed as affected.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity vulnerability. Exploitation requires the attacker to already have editor-level access to the WordPress site, which limits the attack surface to authenticated adversaries with sufficient privileges. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated web application attack where the attacker submits crafted input through the plugin’s form endpoint. Given the need for privileged access, the likelihood of exploitation in the wild is lower than for publicly exploitable flaws, but the impact on an authenticated user remains significant.
OpenCVE Enrichment