S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-2187 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Contact Form 7 Captcha plugin for WordPress affects v. before 0.1.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2187
6.1
CVSS

The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Contact Form 7 Captcha
AFFECTED< 0.1.2SAFE ✓≥ 0.1.2
Updated Aug 22, 2026View on NVD →
Detail

Contact Form 7 Captcha WordPress plugin is a commonly used plugin that helps WordPress site owners protect their contact forms from spam bots. The plugin adds a captcha field to the contact form, which requires users to enter characters from an image to confirm that they are not automated scripts. This feature can save site owners a lot of time and resources that would otherwise be spent on filtering out spam messages.

Recently, a critical vulnerability detected in the Contact Form 7 Captcha WordPress plugin has caught the attention of security experts. The vulnerability, CVE-2022-2187, stems from the fact that the plugin fails to escape the $_SERVER['REQUEST_URI'] parameter before displaying it back to the user. As a result, an attacker can inject malicious JavaScript code into the parameter, leading to Reflected Cross-Site Scripting (XSS) in older web browsers.

The consequences of this vulnerability can be significant, especially for site owners who rely on information submitted through contact forms. An attacker can inject JavaScript code that, when executed, can steal sensitive information, such as login credentials, credit card numbers, and personal data. This information can then be used for further attacks, such as identity theft, financial fraud, and malware dissemination.

As an added benefit, site owners can rely on the pro features of s4e.io platform to stay informed about vulnerabilities in their digital assets. With this platform, they can receive timely alerts and notifications about security threats, as well as access powerful scanning tools and analytics. In summary, while the Contact Form 7 Captcha WordPress plugin is an essential tool for website security, site owners must remain vigilant and take proactive measures to protect against vulnerabilities such as CVE-2022-2187.

 

REFERENCES

Solution Advice

To protect against this vulnerability, site owners can take the following precautions:

  • Install the latest version of the Contact Form 7 Captcha WordPress plugin (v0.1.2 or later), which addresses the vulnerability.
  • Regularly update all plugins and themes used on the site to ensure they are patched against known vulnerabilities.
  • Use a security plugin, such as Wordfence or Jetpack Security, to detect and block malicious traffic.
  • Use a Content Security Policy (CSP) to restrict the execution of JavaScript on the site and prevent XSS attacks.
  • Educate users to be cautious and avoid clicking on suspicious links or downloading unknown files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.