Description
WordPress Plugin Enmask Captcha is prone to malicious redirects. Attackers may leverage this issue to promote spam, distribute malware/backdoors, or to perform all kinds of malicious activities. WordPress Plugin Enmask Captcha version 1.3 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3836)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.17)
WordPress Plugin Smart Forms-when you need more than just a contact form Security Bypass (2.6.70)
WordPress Plugin Captcha by BestWebSoft Multiple Cross-Site Scripting Vulnerabilities (4.1.5)