Stored Cross-site Scripting Vulnerability in Rozx Recaptcha by WordPress
CVE-2025-60177
5.9MEDIUM
What is CVE-2025-60177?
A vulnerability in the Rozx Recaptcha plugin for WordPress allows for the improper neutralization of input during web page generation. This stored XSS issue can be exploited by malicious users to inject arbitrary scripts into the application, potentially compromising user data and leading to unauthorized actions on behalf of users. Affected versions include everything from n/a up to version 0.2.6. It is essential for users of this plugin to apply security measures and update to protected versions to mitigate risks.
Affected Version(s)
Recaptcha – wp <= 0.2.6