Stored Cross-Site Scripting Vulnerability in Invisible Anti-Spam & CAPTCHA Plugin for WordPress
CVE-2026-16145

7.2HIGH

What is CVE-2026-16145?

The Invisible Anti-Spam & CAPTCHA β€” reCAPTCHA Alternative for All Forms plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability. This vulnerability arises from inadequate input sanitization and output escaping concerning the 'action' parameter. As a result, unauthenticated attackers can inject malicious web scripts into pages, which are executed when users access these modified pages. The vulnerability allows the stored payload to be written through any unauthenticated admin-ajax.php request with an action value that corresponds to entries in the plugin's explicit-actions list. These actions are auto-populated for common form builders during activation, posing a significant risk since they lack adequate authentication controls.

Affected Version(s)

Invisible Anti-Spam & CAPTCHA β€” reCAPTCHA Alternative for All Forms 0 <= 5.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivaylo
.