VYPR
Medium severity5.9NVD Advisory· Published Sep 26, 2025· Updated Apr 28, 2026

CVE-2025-60177

CVE-2025-60177

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rozx Recaptcha – wp recaptcha-wp allows Stored XSS.This issue affects Recaptcha – wp: from n/a through <= 0.2.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in WordPress Recaptcha – wp plugin versions ≤ 0.2.6 allows authenticated attackers to inject malicious scripts.

Vulnerability

Description The Recaptcha – wp WordPress plugin (slug: recaptcha-wp) versions from n/a through 0.2.6 contain a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This means input supplied by an authenticated user is not properly sanitized before being stored and later rendered in the admin interface or other pages, allowing arbitrary JavaScript to be injected.

Exploitation

To exploit this issue, an attacker must have at least the required privilege level (e.g., a contributor or higher) to submit input that gets persisted. The attack requires user interaction — a privileged user (such as an administrator) must perform an action like clicking a link, visiting a crafted page, or submitting a form to trigger the stored payload [1]. No authentication bypass is needed beyond the attacker's own account.

Impact

If successfully exploited, the attacker can inject malicious scripts that execute in the context of other users' browsers. This can be used to redirect visitors, display unauthorized advertisements, steal session cookies, or deface the site [1]. The vulnerability has a CVSS v3 score of 5.9 (Medium) and is known to be used in mass-exploit campaigns targeting thousands of WordPress sites.

Mitigation

Users are strongly advised to update the Recaptcha – wp plugin to a patched version as soon as possible. If updating is not feasible, contacting the hosting provider or a web developer for assistance is recommended [1]. No workaround other than disabling the plugin is currently available.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.