CVE-2025-2074
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-2074 is a vulnerability affecting the Advanced Google reCAPTCHA plugin for WordPress. This issue, present in all versions up to 1.29, stems from insufficient escaping on user-supplied data and an absence of sufficient preparation on SQL queries. Authenticated attackers with Subscriber-level access or higher can manipulate the 'sSearch' parameter to inject additional SQL queries, exploiting this weakness most effectively when the plugin settings page hasn't been visited and its welcome message remains undismissed. The consequence of this vulnerability is the extraction of sensitive information from the database.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.