CyberRota Analysis
AI-GeneratedThe Simple CAPTCHA with Cloudflare Turnstile plugin for WordPress versions prior to 1.42.3 is vulnerable due to its shortcode parser processing user-submitted values in Contact Form 7 forms, enabling unauthenticated users to execute arbitrary shortcodes. This could lead to unauthorized actions on the site, potentially compromising its integrity or exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.