First published: Fri May 10 2024(Updated: )
The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress reCAPTCHA Jetpack | <=0.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3941 is classified as a high severity vulnerability due to its potential to allow stored XSS attacks.
To mitigate CVE-2024-3941, update the reCAPTCHA Jetpack WordPress plugin to version 0.2.3 or later.
CVE-2024-3941 is a vulnerability in the reCAPTCHA Jetpack WordPress plugin that lacks CSRF checks and proper sanitization, allowing for stored XSS via CSRF.
CVE-2024-3941 affects users of the reCAPTCHA Jetpack WordPress plugin version 0.2.2 and earlier.
Exploitation of CVE-2024-3941 could lead to unauthorized script execution in users' browsers, compromising site integrity and user data.