PT-2024-28486 · WordPress · Recaptcha Jetpack Wordpress Plugin

Bob Matyas

·

Published

2024-05-10

·

Updated

2024-05-14

·

CVE-2024-3941

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions reCAPTCHA Jetpack WordPress plugin versions through 0.2.2
Description The issue concerns a lack of CSRF check and missing sanitization as well as escaping in certain areas, potentially allowing attackers to inject Stored XSS payloads via a CSRF attack, targeting logged-in admins.
Recommendations For versions through 0.2.2, update to a version that includes the necessary CSRF checks and proper sanitization and escaping to prevent such attacks.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-3941

Affected Products

Recaptcha Jetpack Wordpress Plugin