CVE-2024-3941

CVE-2024-3941: reCAPTCHA Jetpack <= 0.2.2 - Stored XSS via CSRF

Vendor Unknown
Product reCAPTCHA Jetpack
Published May 10, 2024
Last update March 28, 2025

CVSS base score

What the vulnerability does

Description

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

Key dates

Disclosure timeline

May 10, 2024 CVE published
March 28, 2025 Record updated