CVE-2026-85116: Simple CAPTCHA with Cloudflare Turnstile 1.2.2 - 1.42.1 - Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to this issue?
Sites using the WordPress Simple CAPTCHA with Cloudflare Turnstile plugin in versions 1.2.2 through versions earlier than 1.42.3 are affected when Contact Form 7 forms process and render visitor-submitted values. The impact depends on which shortcodes are registered on the site.
What does an attacker need to exploit it?
An attacker does not need an account or user interaction. They need to be able to submit values to an affected Contact Form 7 form so those values are processed during form rendering.
What version should be deployed to leave the listed affected range?
Upgrade the plugin to version 1.42.3 or later. The vulnerability description identifies versions before 1.42.3 as affected.