Impact
The vulnerability exists in the Simple CAPTCHA with Cloudflare Turnstile WordPress plugin when versions from 1.2.2 up to 1.42.2 are used. The plugin applies the Contact Form 7 shortcode parser to the entire rendered form, including data that visitors submit. This allows unauthenticated users to inject any shortcode registered on the site into the submitted form, leading to the execution of that shortcode without authentication. The flaw effectively permits arbitrary code execution, data disclosure, or other unintended actions, as the shortcodes can invoke any registered functions on the server.
Affected Systems
Affected systems are WordPress sites running the Simple CAPTCHA with Cloudflare Turnstile plugin version 1.2.2 through 1.42.2, inclusive. The weakness arises whenever the plugin parses a Contact Form 7 field that has been repopulated from user input.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity. Although no public exploitation has been reported and the vulnerability is not listed in the CISA KEV catalog, an attacker can exploit the flaw simply by submitting a crafted form: the attacker does not need administrative privileges or any special credentials. The lack of an exploit indicator does not reduce the potential risk, because the flaw opens a vector for arbitrary execution via shortcodes, which can lead to full site compromise in an environment where plugins expose powerful functionality.
OpenCVE Enrichment