WordPress security by component
Simple CAPTCHA with Cloudflare Turnstile
Simple CAPTCHA with Cloudflare Turnstile (simple-captcha-with-cloudflare-turnstile) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
simple-captcha-with-cloudflare-turnstileLatest vulnerability
CVE-2026-85116: Simple CAPTCHA with Cloudflare Turnstile executes submitted shortcodes
Simple CAPTCHA with Cloudflare Turnstile from 1.2.2 through versions below 1.42.3 runs the WordPress shortcode parser over an entire rendered Contact Form 7 form, including values supplied by an unauthenticated visitor. An attacker can therefore invoke arbitrary shortcodes registered on the site. The resulting impact depends on which shortcodes other active plugins expose; the authoritative export does not identify a universal code-execution path or the affected function name.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-85116
Simple CAPTCHA with Cloudflare Turnstile executes submitted shortcodes
Simple CAPTCHA with Cloudflare Turnstile from 1.2.2 through versions below 1.42.3 runs the WordPress shortcode parser over an entire rendered Contact Form 7 form, including values supplied by an unauthenticated visitor. An attacker can therefore invoke arbitrary shortcodes registered on the site. The resulting impact depends on which shortcodes other active plugins expose; the authoritative export does not identify a universal code-execution path or the affected function name.
|
1.42.3 |
CVE6.5
NVDPending
|