Description
The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Shortcode Execution
Action: Apply Patch
AI Analysis

Impact

The Contact Form 7 Captcha plugin contains a flaw that causes the shortcode parser to run over the entire form, including visitor-supplied data, enabling arbitrary shortcode execution. This is a code execution vulnerability described by CWE-74. If an attacker can inject shortcodes, they could trigger any PHP code registered with WordPress, potentially compromising confidentiality, integrity and availability of the site. The CVE description explicitly states that unauthenticated users can trigger this behavior, emphasizing its impact on sites exposing the form.

Affected Systems

All WordPress sites that install the Contact Form 7 Captcha plugin before version 0.1.9 are impacted. The plugin is listed under Unknown:Contact Form 7 Captcha. Any site that hosts a public Contact Form 7 form using this plugin is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of 0.00183 shows a very low exploitation probability, leaving the real-world frequency uncertain. The vulnerability is not listed in the CISA KEV catalog and no public exploitation code has been reported. The likely attack vector is an unauthenticated visitor submitting specially crafted form data; based on the description, it is inferred that the attacker could exploit registered shortcodes that execute PHP code, potentially leading to full-site compromise.

Generated by OpenCVE AI on September 9, 2026 at 18:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Contact Form 7 Captcha plugin to version 0.1.9 or later where the flaw has been addressed.
  • If an upgrade is not immediately possible, deactivate or remove the plugin from all sites that accept public form submissions to eliminate the attack surface.
  • Until a patch is applied, consider using a security plugin or firewall rule that blocks the execution of user-submitted shortcodes to reduce the risk of exploitation.

Generated by OpenCVE AI on September 9, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Contact Form 7 Captcha Project
Contact Form 7 Captcha Project contact Form 7 Captcha
Wordpress
Wordpress wordpress
Vendors & Products Contact Form 7 Captcha Project
Contact Form 7 Captcha Project contact Form 7 Captcha
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-74
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
Title Contact Form 7 Captcha 0.1.7 - 0.1.8 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Contact Form 7 Captcha Project Contact Form 7 Captcha
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:23:41.750Z

Reserved: 2026-09-03T07:55:26.694Z

Link: CVE-2026-85117

cve-icon Vulnrichment

Updated: 2026-09-09T15:21:47.492Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T07:16:58.647

Modified: 2026-09-09T16:17:13.383

Link: CVE-2026-85117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')