CVE-2026-16146
WordPress Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-16146 is a SQL Injection vulnerability in the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" WordPress plugin (slug: gdpr-compliant-recaptcha-for-all-forms) by matthiasnordwig. All versions up to and including 5.1 are affected. The flaw allows authenticated attackers with editor-level access or above to inject additional SQL queries via Pattern JSON Keys/Values, enabling extraction of sensitive information from the database. It carries a CVSS v3.1 base score of 4.9 (Medium) and was published on August 15, 2026 (Wordfence, ENISA EUVD).

Detalhes técnicos

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command — SQL Injection). It stems from insufficient escaping of user-supplied input and a lack of proper SQL query preparation in the plugin's code, specifically in class-option.php (lines 290, 292) and class-message-page.php (lines 428, 451, 519). An authenticated attacker with editor-level privileges or higher can manipulate Pattern JSON keys or values to append malicious SQL clauses to existing queries, enabling data extraction from the WordPress database (Wordfence, WordPress Trac).

Impacto

Successful exploitation allows an authenticated attacker to extract sensitive information from the WordPress database, including user credentials, personal data, and site configuration. The impact is limited to confidentiality (no integrity or availability impact), and exploitation requires editor-level authentication, reducing the risk of mass exploitation. However, database exposure could facilitate further attacks such as credential theft or privilege escalation within the WordPress environment (Wordfence, ENISA EUVD).

Exploração

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the publication date. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated editor-level access. The EPSS score is approximately 0.294%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, ENISA EUVD).

Etapas de exploração

  1. Reconnaissance: Identify WordPress sites running the "Invisible Anti-Spam & CAPTCHA" plugin (slug: gdpr-compliant-recaptcha-for-all-forms) at version 5.1 or below, using tools like WPScan or manual inspection of plugin directories.
  2. Obtain Editor-Level Access: Authenticate to the WordPress admin panel with an account holding editor-level privileges or higher (e.g., via compromised credentials or social engineering).
  3. Locate Vulnerable Input: Navigate to the plugin's admin settings where Pattern JSON Keys/Values are configured, corresponding to the vulnerable code paths in class-option.php and class-message-page.php.
  4. Inject Malicious SQL Payload: Craft a JSON key or value containing SQL injection syntax (e.g., ' UNION SELECT user_login, user_pass FROM wp_users-- -) that appends to the existing SQL query without proper escaping or parameterization.
  5. Extract Sensitive Data: Submit the crafted input and observe the plugin's response or database behavior to retrieve sensitive information such as WordPress user credentials or other database contents (Wordfence, WordPress Trac).

Indicadores de compromisso

  • Logs: WordPress or web server access logs showing unusual POST requests to plugin admin pages (e.g., paths related to gdpr-compliant-recaptcha-for-all-forms settings) containing SQL metacharacters such as ', UNION, SELECT, or -- in JSON parameter values.
  • Database: Unexpected or anomalous database queries in MySQL slow query logs or general query logs involving UNION SELECT or stacked queries originating from the WordPress application user.
  • File System: No specific file artifacts are expected, but review for unauthorized changes to plugin files in wp-content/plugins/gdpr-compliant-recaptcha-for-all-forms/.
  • User Activity: WordPress audit logs (if enabled) showing editor-level accounts accessing or modifying plugin pattern/JSON settings at unusual times or frequencies.

Mitigação e soluções alternativas

Users should update the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" plugin to a version beyond 5.1, as the fix was committed in changeset 3633500 on the WordPress plugin repository. Until an update is applied, site administrators should restrict editor-level access to trusted users only and consider temporarily deactivating the plugin. Monitoring database query logs for anomalous SQL patterns is also recommended as a compensating control (WordPress Trac Changeset, Wordfence).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado WordPress Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NãoSimAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NãoSimAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NãoSimAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NãoSimAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NãoSimAug 23, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades