Junglewise Threat Intelligence

CVE-2026-57365: Hitesh Chandwani reCAPTCHA for Asgaros Forum DOM-Based XSS

CVE-2026-57365 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Executive brief

A vulnerability exists in the reCAPTCHA plugin for Asgaros Forum, a tool used to prevent automated spam on WordPress discussion boards. An attacker could use this flaw to inject malicious scripts into the website, potentially leading to unauthorized redirects, the display of fraudulent content, or the theft of user session information. This risk is particularly relevant for sites where users interact with forum content, as the attack requires a victim to perform a specific action like clicking a link.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum plugin for WordPress. The flaw stems from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts into the Document Object Model (DOM). Exploitation requires 'Subscriber' level privileges and some form of user interaction, such as a victim clicking a specially crafted link. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's browser, which can be used to bypass same-origin policies or hijack sessions. The issue is resolved in version 1.1.1.

Affected products

  • Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum <= 1.1.0

Timeline

  • 2026-04-30: other: Reported by HieuPenguinnn
  • 2026-07-06: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: NVD publication date

References