Impact
The Contact Form 7 Captcha plugin contains a flaw that causes the shortcode parser to run over the entire form, including visitor-supplied data, enabling arbitrary shortcode execution. This is a code execution vulnerability described by CWE-74. If an attacker can inject shortcodes, they could trigger any PHP code registered with WordPress, potentially compromising confidentiality, integrity and availability of the site. The CVE description explicitly states that unauthenticated users can trigger this behavior, emphasizing its impact on sites exposing the form.
Affected Systems
All WordPress sites that install the Contact Form 7 Captcha plugin before version 0.1.9 are impacted. The plugin is listed under Unknown:Contact Form 7 Captcha. Any site that hosts a public Contact Form 7 form using this plugin is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of 0.00183 shows a very low exploitation probability, leaving the real-world frequency uncertain. The vulnerability is not listed in the CISA KEV catalog and no public exploitation code has been reported. The likely attack vector is an unauthenticated visitor submitting specially crafted form data; based on the description, it is inferred that the attacker could exploit registered shortcodes that execute PHP code, potentially leading to full-site compromise.
OpenCVE Enrichment