CVE-2025-48243: WordPress reCAPTCHA for all plugin <= 2.26 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.26.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in sminozzi reCAPTCHA for all recaptcha-for-all allows Cross Site Request Forgery.This issue affects reCAPTCHA for all: from n/a through <= 2.26.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48243?
CVE-2025-48243 is considered a high-severity vulnerability due to its potential for Cross-Site Request Forgery (CSRF) attacks.
How do I fix CVE-2025-48243?
To fix CVE-2025-48243, update the Bill Minozzi reCAPTCHA plugin to version 2.27 or later.
What software is affected by CVE-2025-48243?
CVE-2025-48243 affects the Bill Minozzi reCAPTCHA for all versions up to and including 2.26.
What types of attacks are possible with CVE-2025-48243?
CVE-2025-48243 allows attackers to perform Cross-Site Request Forgery (CSRF) attacks, potentially leading to unauthorized actions.
Is CVE-2025-48243 specific to any platform?
CVE-2025-48243 specifically affects reCAPTCHA implementations in WordPress and other applications using the Bill Minozzi plugin.