What is CVE-2026-16145?
CVE-2026-16145 is a Stored Cross-Site Scripting (XSS) vulnerability in the 'Invisible Anti-Spam & CAPTCHA' plugin for WordPress. Insufficient sanitization of the 'action' parameter allows unauthenticated attackers to inject malicious scripts. This affects versions up to 5.1, users should update the plugin immediately.
Azərbaycanca: CVE-2026-16145, WordPress üçün 'Invisible Anti-Spam & CAPTCHA' plaginində aşkarlanmış Stored Cross-Site Scripting (XSS) zəifliyidir. 'action' parametrindəki kifayət qədər olmayan giriş təmizlənməsi səbəbindən autentifikasiya olunmamış hücumçulara zərərli skript yeritməyə imkan verir. Bu problem 5.1-ə qədər olan versiyaları təsirləndirir, istifadəçilərə plagini yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Invisible Anti-Spam & CAPTCHA plugin are affected by CVE-2026-16145?
This vulnerability affects all versions of the plugin up to 5.1.
What does the CVE-2026-16145 vulnerability allow unauthenticated attackers to do?
It allows unauthenticated attackers to inject malicious scripts due to insufficient sanitization of the 'action' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.