CVE-2025-8280

The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:iambriansreed:contact_form_7_recaptcha:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2025-09-12 06:15

Updated : 2026-06-17 10:06


NVD link : CVE-2025-8280

Mitre link : CVE-2025-8280

CVE.ORG link : CVE-2025-8280


JSON object : View

Products Affected

iambriansreed

  • contact_form_7_recaptcha
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')