CF7 Invisible reCAPTCHA
CF7 Invisible reCAPTCHA has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2023; all 2 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for CF7 Invisible reCAPTCHA has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Rio Darmawan. CF7 Invisible reCAPTCHA is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2018-21012CF7 Invisible reCAPTCHA < 1.3.2 - Cross-Site Scripting
Read the full analysisVulnerability Records

CF7 Invisible reCAPTCHA
Author
Vsourz Digital
CF7 Invisible reCAPTCHA plugin is an effective solution that secures your Contact form 7 forms on WordPress websites from spam entries while letting human pass over easily. Just a single click they’ll confirm they are not a robot. Activated only in cases where Google suspects that the visitor is not a human. This plugin utilizes the popular anti-spam library, Google invisible reCAPTCHA, to help your blog stay clear of spams. All it takes is 2 easy step to make your website stand out from rest of your competitors. Install the plugin. Add site and secret key. It’s easy to use. Read How to use? section to find out more about the CF7 Invisible reCAPTCHA configurations Need Support? wp.support@vsourz.com Features Protection against disabled JavaScript from the browser. Easy and simple settings for quick setup without a change in code. Option to Enable/Disable Protection for Contact Form 7. Easy to Exclude Invisible reCAPTCHA for the particular form. Option to Show/Hide Google reCaptcha Badge. Easy to Manage Badge Position. Easy to validate your Site Key and Secret key from CF7 Invisible reCAPTCHA menu. How to use? Install Plugin via WordPress Admin – Go to Admin > Plugins > Add New. Add CF7 Invisible reCAPTCHA Go To CF7 Invisible reCAPTCHA. Enable Protection for Contact Form 7. Add Site Key and Secret Key. Validate Site Key and Secret Key. License GPLv2 – https://www.gnu.org/licenses/gpl-2.0.html
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C