PT-2025-37295 · WordPress · Contact Form 7 Captcha

Bob Matyas

·

Published

2025-09-12

·

Updated

2026-03-16

·

CVE-2025-8280

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Contact Form 7 reCAPTCHA WordPress plugin versions through 1.2.0
Description: The plugin does not escape the $ SERVER['REQUEST URI'] parameter before outputting it, potentially leading to Reflected Cross-Site Scripting in older web browsers.
Recommendations: Update to a version beyond 1.2.0.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-8280

Affected Products

Contact Form 7 Captcha