Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 &amp; v3) for Asgaros Forum: from n/a through <= 1.1.0.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reCAPTCHA (v2 & v3) for Asgaros Forum plugin contains a DOM‑based cross‑site scripting flaw that fails to neutralize user input when rendering a page. An attacker can inject malicious code via crafted input—such as through a URL or form to execute arbitrary JavaScript in the victim’s browser, potentially stealing session data or performing other client‑side attacks.

Affected Systems

WordPress installations that run the reCAPTCHA (v2 & v3) for Asgaros Forum plugin by Hitesh Chandwani are affected. All versions through 1.1.0, inclusive, are vulnerable; any site using those or earlier releases is at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. With no listing in the CISA KEV catalog, no known widespread attacks have been recorded. The attack vector is user‑initiated interaction with the compromised page, for instance by clicking a malicious link or submitting a manipulated form. The impact remains client‑side, but it can lead to session hijacking, data theft, or further malicious activity.

Generated by OpenCVE AI on July 31, 2026 at 12:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the reCAPTCHA (v2 & v3) for Asgaros Forum plugin to a release newer than 1.1.0 to eliminate the vulnerable code.
  • If an upgrade cannot be performed immediately, disable or remove the vulnerable plugin from the WordPress installation to eliminate the attack surface.
  • Deploy a web application firewall or a security plugin that blocks common XSS patterns to provide temporary protection until a patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 12:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Hitesh Chandwani
Hitesh Chandwani recaptcha (v2 &amp; V3) For Asgaros Forum
Wordpress
Wordpress wordpress
Vendors & Products Hitesh Chandwani
Hitesh Chandwani recaptcha (v2 &amp; V3) For Asgaros Forum
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 &amp; v3) for Asgaros Forum: from n/a through <= 1.1.0.
Title WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Hitesh Chandwani Recaptcha (v2 &amp; V3) For Asgaros Forum
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:54.165Z

Reserved: 2026-06-24T12:45:46.645Z

Link: CVE-2026-57365

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')