WordPress Contact Form 7 Captcha plugin before 0.1.2 contains a reflected cross-site scripting vulnerability. It does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute.
id: CVE-2022-2187
info:
name: WordPress Contact Form 7 Captcha <0.1.2 - Cross-Site Scripting
au
...