CVE-2026-85116

MEDIUMCVSS 6.5/10

Last modified

CVE-2026-85116 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site..

Description

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
UnknownSimple CAPTCHA with Cloudflare Turnstile>= 1.2.2, < 1.42.3

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2026-85116?
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
How severe is CVE-2026-85116?
CVE-2026-85116 has a CVSS score of 6.5/10 (MEDIUM severity).
How do I fix CVE-2026-85116?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-85116?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST