
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-16146 is a SQL Injection vulnerability in the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" WordPress plugin (slug: gdpr-compliant-recaptcha-for-all-forms) by matthiasnordwig. All versions up to and including 5.1 are affected. The flaw allows authenticated attackers with editor-level access or above to inject additional SQL queries via Pattern JSON Keys/Values, enabling extraction of sensitive information from the database. It carries a CVSS v3.1 base score of 4.9 (Medium) and was published on August 15, 2026 (Wordfence, ENISA EUVD).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command — SQL Injection). It stems from insufficient escaping of user-supplied input and a lack of proper SQL query preparation in the plugin's code, specifically in class-option.php (lines 290, 292) and class-message-page.php (lines 428, 451, 519). An authenticated attacker with editor-level privileges or higher can manipulate Pattern JSON keys or values to append malicious SQL clauses to existing queries, enabling data extraction from the WordPress database (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker to extract sensitive information from the WordPress database, including user credentials, personal data, and site configuration. The impact is limited to confidentiality (no integrity or availability impact), and exploitation requires editor-level authentication, reducing the risk of mass exploitation. However, database exposure could facilitate further attacks such as credential theft or privilege escalation within the WordPress environment (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the publication date. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated editor-level access. The EPSS score is approximately 0.294%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, ENISA EUVD).
gdpr-compliant-recaptcha-for-all-forms) at version 5.1 or below, using tools like WPScan or manual inspection of plugin directories.class-option.php and class-message-page.php.' UNION SELECT user_login, user_pass FROM wp_users-- -) that appends to the existing SQL query without proper escaping or parameterization.gdpr-compliant-recaptcha-for-all-forms settings) containing SQL metacharacters such as ', UNION, SELECT, or -- in JSON parameter values.UNION SELECT or stacked queries originating from the WordPress application user.wp-content/plugins/gdpr-compliant-recaptcha-for-all-forms/.Users should update the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" plugin to a version beyond 5.1, as the fix was committed in changeset 3633500 on the WordPress plugin repository. Until an update is applied, site administrators should restrict editor-level access to trusted users only and consider temporarily deactivating the plugin. Monitoring database query logs for anomalous SQL patterns is also recommended as a compensating control (WordPress Trac Changeset, Wordfence).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."