VULNERABILITY BRIEFING: CVE-2026-4512 OVERVIEW The reCaptcha by WebDesignBy WordPress plugin versions prior to 2.0 contains an improper output encoding vulnerability in the grecaptcha_js() function. The Site Key setting is not properly sanitized or escaped before being output within a JavaScript string context, allowing administrators with restricted privileges on multisite WordPress installations to inject malicious JavaScript code. SEVERITY The vulnerability carries a CVSS v3.1 score of 3.5 (LOW) with a network-based attack vector, low complexity, and high privilege requirement. Exploitation requires administrator-level access and user interaction, limiting its impact to low-level information disclosure and integrity compromise affecting the WordPress login page. The EPSS score of 0.000090 indicates minimal real-world exploitation probability compared to other disclosed vulnerabilities. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, exploit code is not publicly available, and community attention remains minimal. The FAUCET risk score of 28.0/100 and inactive hot list status further indicate this is a low-priority threat with negligible current exploitation activity. Organizations should prioritize patching to version 2.0 or later as part of routine WordPress plugin maintenance rather than emergency response procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Unknown | ReCaptcha By WebDesignBy | >= 0, < 2.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.