First published: Thu Jan 16 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Stanisław Skonieczny Secure CAPTCHA allows Stored XSS.This issue affects Secure CAPTCHA: from n/a through 1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Secure CAPTCHA | >n/a<=1.2 | |
WordPress Captcha | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23693 is considered a high severity vulnerability due to its potential for Cross-Site Request Forgery leading to Stored XSS.
To fix CVE-2025-23693, update the Secure CAPTCHA plugin to version 1.3 or later, as this version addresses the vulnerability.
CVE-2025-23693 affects versions of Stanisław Skonieczny Secure CAPTCHA from n/a through 1.2 and WordPress Secure CAPTCHA up to version 1.2.
CVE-2025-23693 is a Cross-Site Request Forgery (CSRF) vulnerability that allows for Stored Cross-Site Scripting (XSS).
Yes, attackers can exploit CVE-2025-23693 to execute arbitrary scripts in the context of a user’s session in the affected applications.