CVE-2025-8280: Contact Form 7 reCAPTCHA <= 1.2.0 - Reflected XSS via $_SERVER['REQUEST_URI']
The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $SERVER['REQUESTURI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8280?
CVE-2025-8280 has a medium severity rating due to its potential for Reflected Cross-Site Scripting vulnerabilities.
How do I fix CVE-2025-8280?
To fix CVE-2025-8280, you should upgrade the Contact Form 7 reCAPTCHA plugin to version 1.2.1 or later.
Which versions of the Contact Form 7 reCAPTCHA plugin are affected by CVE-2025-8280?
CVE-2025-8280 affects all versions of the Contact Form 7 reCAPTCHA plugin up to and including version 1.2.0.
What type of vulnerability is CVE-2025-8280?
CVE-2025-8280 is a Reflected Cross-Site Scripting vulnerability that can be exploited in certain web browsers.
What are the potential impacts of CVE-2025-8280?
If exploited, CVE-2025-8280 could allow attackers to execute malicious scripts in the context of a user's session.