Impact
The reCAPTCHA (v2 & v3) for Asgaros Forum plugin contains a DOM‑based cross‑site scripting flaw that fails to neutralize user input when rendering a page. An attacker can inject malicious code via crafted input—such as through a URL or form to execute arbitrary JavaScript in the victim’s browser, potentially stealing session data or performing other client‑side attacks.
Affected Systems
WordPress installations that run the reCAPTCHA (v2 & v3) for Asgaros Forum plugin by Hitesh Chandwani are affected. All versions through 1.1.0, inclusive, are vulnerable; any site using those or earlier releases is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. With no listing in the CISA KEV catalog, no known widespread attacks have been recorded. The attack vector is user‑initiated interaction with the compromised page, for instance by clicking a malicious link or submitting a manipulated form. The impact remains client‑side, but it can lead to session hijacking, data theft, or further malicious activity.
OpenCVE Enrichment