SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-85116

MEDIUM · CVSS 6.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Simple CAPTCHA with Cloudflare Turnstile plugin for WordPress versions prior to 1.42.3 is vulnerable due to its shortcode parser processing user-submitted values in Contact Form 7 forms, enabling unauthenticated users to execute arbitrary shortcodes. This could lead to unauthorized actions on the site, potentially compromising its integrity or exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-85116
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%
WordPress

Original NVD Description

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.