Contact Form 7 Captcha Project maintains a WordPress plugin focused on adding CAPTCHA protection to contact forms, with its vulnerability profile centered on the single product Contact Form 7 Captcha and rooted in web application input-handling weaknesses such as cross-site scripting and cross-site request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contact Form 7 Captcha Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2187MEDIUM The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflec | Jul 17, 2022 | 6.1 | 31 | NO | YES |
CVE-2021-24565HIGH The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_ | Aug 23, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contact Form 7 Captcha Project.
Media articles that mention a CVE ID that affects a product developed by Contact Form 7 Captcha Project — matched by CVE ID, not by vendor name.