PatchSiren

matthiasnordwig CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM matthiasnordwig CVE published 2026-08-15

CVE-2026-16146

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1. This vulnerability is due to insufficient escaping on user-supplied parameters and a lack of sufficient preparation on the existing SQL query. An authenticated attacker with editor-level access and above [truncated]

HIGH matthiasnordwig CVE published 2026-08-15

CVE-2026-16145

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The stored payload can be written by any unaut [truncated]

MEDIUM matthiasnordwig CVE published 2026-08-15

CVE-2026-16094

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1. This vulnerability is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Authenticated attackers with editor-level access and above can ex [truncated]