{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/invisible-anti-spam--captcha--recaptcha-alternative-for-all-forms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-16145"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Invisible Anti-Spam \u0026 CAPTCHA — reCAPTCHA Alternative for All Forms"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Invisible Anti-Spam \u0026amp; CAPTCHA plugin for WordPress, in versions 5.1 and earlier, contains a critical Stored Cross-Site Scripting (XSS) vulnerability. The flaw exists due to insufficient sanitization and escaping of the 'action' parameter when processed by the plugin's 'admin-ajax.php' handler. An attacker can submit unauthenticated HTTP requests to this endpoint, triggering the injection of arbitrary JavaScript into the application's database. Because the plugin auto-populates common form builder actions at activation, these entry points are publicly accessible without authentication. Successful exploitation allows for the execution of malicious scripts whenever an administrator or user views the affected page, potentially leading to session hijacking or unauthorized administrative actions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects all sites utilizing the Invisible Anti-Spam \u0026amp; CAPTCHA plugin up to version 5.1. Successful exploitation enables unauthenticated attackers to execute arbitrary code in the context of the victim's browser session. In a WordPress environment, this frequently leads to full administrative account takeover, site defacement, or the injection of persistent malicious redirects and malware distribution scripts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Invisible Anti-Spam \u0026amp; CAPTCHA plugin to the latest available version beyond 5.1 immediately.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP POST requests to admin-ajax.php containing suspicious characters (e.g., \u0026lt;script\u0026gt;, alert(), or event handlers) within the 'action' parameter.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to validate input against the 'action' parameter on WordPress sites to block non-alphanumeric character injections.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T06:16:48Z","date_published":"2026-08-15T06:16:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wordpress-xss/","summary":"An unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the Invisible Anti-Spam \u0026 CAPTCHA plugin (\u003c= 5.1) allows attackers to inject malicious scripts via the action parameter in admin-ajax.php.","title":"Stored Cross-Site Scripting in Invisible Anti-Spam \u0026 CAPTCHA Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-wordpress-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Invisible Anti-Spam \u0026 CAPTCHA — ReCAPTCHA Alternative for All Forms","version":"https://jsonfeed.org/version/1.1"}