Reflected XSS in Are You Robot Google reCAPTCHA for WordPress
CVE-2025-28928
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 March 2025
What is CVE-2025-28928?
A reflected XSS vulnerability in the Are You Robot Google reCAPTCHA WordPress plugin allows attackers to inject malicious scripts into webpages. When users interact with the compromised site, the injected script executes in their browsers, potentially leading to unauthorized actions and data theft. This security flaw affects all installations of the plugin up to version 2.2, making it critical for users to update their software to mitigate risks.
Affected Version(s)
Are you robot google recaptcha for wordpress <= 2.2
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Thi Huyen Trang - Skalucy (Patchstack Alliance)