cleantalk
Vulnerabilities and Security Researches

reCAPTCHA Jetpack, CVE-2024-3941

CVE, Research URL

CVE-2024-3941

Application

reCAPTCHA Jetpack

Published on
May 14, 2024
Research Description
The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.
Affected versions
Min -, max 0.2.2.
Status
vulnerable