PatchSiren cyber security CVE debrief
CVE-2026-16145 matthiasnordwig CVE debrief
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The stored payload can be written by any unauthenticated admin-ajax.php request whose action value matches an entry in the plugin's explicit-actions list. This list is auto-populated for common form builders at activation and requires no authentication gate to reach the save path. Administrators of WordPress installations using this plugin should be aware of the potential risks and take immediate action to protect their sites.
- Vendor
- matthiasnordwig
- Product
- Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Administrators of WordPress installations using the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin, security teams monitoring for potential XSS attacks, and users of the affected plugin versions should prioritize updating to a patched version to prevent potential XSS attacks. Additionally, security teams should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.
Technical summary
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1. This is due to insufficient input sanitization and output escaping. An unauthenticated attacker can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability affects all versions of the plugin up to 5.1, and the stored payload can be written by any unauthenticated admin-ajax.php request whose action value matches an entry in the plugin's explicit-actions list.
Defensive priority
Administrators of WordPress installations using the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin should prioritize updating to a patched version to prevent potential XSS attacks.
Recommended defensive actions
- Update to a patched version of the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin
- Monitor for suspicious admin-ajax.php requests
- Implement additional security measures to detect and prevent XSS attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record indicates that the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter. The vulnerability affects all versions up to, and including, 5.1. The stored payload can be written by any unauthenticated admin-ajax.php request whose action value matches an entry in the plugin's explicit-actions list.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16145 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16145
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16145 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16145
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gdpr-compliant-recaptcha-for-all-forms/tags/5.0/includes/class-message-page.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gdpr-compliant-recaptcha-for-all-forms/tags/5.0/includes/class-stamp.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gdpr-compliant-recaptcha-for-all-forms/tags/5.0/includes/class-stamp.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3633500/gdpr-compliant-recaptcha-for-all-forms
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.