PT-2025-13445 · WordPress · Advanced Google Recaptcha Plugin For Wordpress

Published

2025-03-28

·

Updated

2025-03-29

·

CVE-2025-2074

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advanced Google reCAPTCHA plugin for WordPress versions up to 1.29
Description The issue allows for generic SQL Injection via the sSearch parameter due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries, particularly when the plugin’s settings page hasn’t been visited and its welcome message has not been dismissed. The issue can be used to extract sensitive information from the database.
Recommendations For versions up to 1.29, update to version 1.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation. Avoid using the sSearch parameter in the affected plugin until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2074

Affected Products

Advanced Google Recaptcha Plugin For Wordpress