CVE-2026-85116: Simple CAPTCHA with Cloudflare Turnstile 1.2.2 - 1.42.1 - Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation

Published Sep 11, 2026
·
Updated

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

Affected Software

1 affected component
WordPress Simple CAPTCHA with Cloudflare Turnstile>=1.2.2<1.42.3

Event History

Sep 11, 2026
CVE Published
via MITRE·10:56 AM
Data Sourced
via MITRE·10:56 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to this issue?

Sites using the WordPress Simple CAPTCHA with Cloudflare Turnstile plugin in versions 1.2.2 through versions earlier than 1.42.3 are affected when Contact Form 7 forms process and render visitor-submitted values. The impact depends on which shortcodes are registered on the site.

2

What does an attacker need to exploit it?

An attacker does not need an account or user interaction. They need to be able to submit values to an affected Contact Form 7 form so those values are processed during form rendering.

3

What version should be deployed to leave the listed affected range?

Upgrade the plugin to version 1.42.3 or later. The vulnerability description identifies versions before 1.42.3 as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203