MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter
Published Jan 10, 2008
4.3
MEDIUMCVSS 2.0
EPSS 1.85%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.