vulnerability

WordPress Plugin: contact-form-7-simple-recaptcha: CVE-2022-2187: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Jun 27, 2022
Added
May 15, 2025
Modified
May 15, 2025

Description

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

Solution

contact-form-7-simple-recaptcha-plugin-cve-2022-2187
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.