Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29023 | The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers. |
Mon, 16 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iambriansreed
Iambriansreed contact Form 7 Recaptcha |
|
| CPEs | cpe:2.3:a:iambriansreed:contact_form_7_recaptcha:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Contact Form 7 Captcha Project
Contact Form 7 Captcha Project contact Form 7 Captcha |
Iambriansreed
Iambriansreed contact Form 7 Recaptcha |
Fri, 13 Feb 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contact Form 7 Captcha Project
Contact Form 7 Captcha Project contact Form 7 Captcha |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:contact_form_7_captcha_project:contact_form_7_captcha:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Contact Form 7 Captcha Project
Contact Form 7 Captcha Project contact Form 7 Captcha |
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 12 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers. | |
| Title | Contact Form 7 reCAPTCHA <= 1.2.0 - Reflected XSS via $_SERVER['REQUEST_URI'] | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-09-12T16:22:30.609Z
Reserved: 2025-07-28T13:37:03.227Z
Link: CVE-2025-8280
Updated: 2025-09-12T16:11:01.981Z
Status : Analyzed
Published: 2025-09-12T06:15:43.660
Modified: 2026-03-16T18:23:29.957
Link: CVE-2025-8280
No data.
OpenCVE Enrichment
Updated: 2025-09-15T10:43:56Z
EUVD