๐Ÿ” CVE Alert

CVE-2026-85117

MEDIUM 6.5

Contact Form 7 Captcha 0.1.7 - 0.1.8 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

Vendor unknown
Product contact form 7 captcha
Published Sep 9, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown contact form 7 captcha

Be the first to know when new medium vulnerabilities affecting unknown contact form 7 captcha are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Contact Form 7 Captcha
0.1.7 < 0.1.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e791e4a6-5ec1-49c7-9448-1d83ec4f4905/

Credits

Jakub Herman WPScan