SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85117

MEDIUM · CVSS 6.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Contact Form 7 Captcha plugin for WordPress versions prior to 0.1.9 is vulnerable due to its improper handling of user-submitted data, allowing unauthenticated users to execute arbitrary shortcodes within the rendered forms. This could lead to unauthorized actions or information disclosure on the site. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-85117
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%
WordPress

Original NVD Description

The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.