Reflected XSS Flaw in NotFound Customizable Captcha and Contact Us Plugin
CVE-2025-23503
7.1HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 22 January 2025
Summary
The NotFound Customizable Captcha and Contact Us plugin is susceptible to a reflected cross-site scripting (XSS) vulnerability. This security issue allows attackers to inject malicious scripts through manipulated input fields, potentially compromising user data and site integrity. The vulnerability affects versions up to 1.0.2, necessitating prompt attention and remediation by users of this plugin.
Affected Version(s)
Customizable Captcha and Contact Us <= 1.0.2
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)