Reflected Cross-Site Scripting in Gotcha Gesture-based Captcha for WordPress
CVE-2025-2482
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 March 2025
What is CVE-2025-2482?
The Gotcha | Gesture-based Captcha plugin for WordPress contains a flaw that allows for reflected Cross-Site Scripting (XSS) via the 'menu' parameter in all versions up to and including 1.0.0. This vulnerability arises from inadequate input sanitization and output escaping, enabling unauthenticated attackers to inject malicious web scripts. If users are deceived into performing specific actions, such as clicking on crafted links, they may inadvertently execute the injected scripts within their browsers.
Affected Version(s)
Gotcha | Gesture-based Captcha * <= 1.0.0