CVE-2026-85117

The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 07:16

Updated : 2026-09-09 16:17


NVD link : CVE-2026-85117

Mitre link : CVE-2026-85117

CVE.ORG link : CVE-2026-85117


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')