WordPress Plugin Vulnerabilities

Simple Cloudflare Turnstile < 1.38.1 - Unauthenticated CAPTCHA Bypass via Session Replay

Description

The plugin is vulnerable to a CAPTCHA bypass via session replay due to caching a successful Turnstile verification response in the PHP session and failing to invalidate it after use. This makes it possible for unauthenticated attackers to solve the CAPTCHA once and reuse the session to bypass the check on subsequent requests.

Affects Plugins

References

Miscellaneous

Original Researcher
David Marín
Verified
No

Timeline

Publicly Published
2026-05-08 (about 3 months ago)
Added
2026-05-12 (about 3 months ago)
Last Updated
2026-05-12 (about 3 months ago)

Other