WordPress Plugin Vulnerabilities
Simple Cloudflare Turnstile < 1.38.1 - Unauthenticated CAPTCHA Bypass via Session Replay
Description
The plugin is vulnerable to a CAPTCHA bypass via session replay due to caching a successful Turnstile verification response in the PHP session and failing to invalidate it after use. This makes it possible for unauthenticated attackers to solve the CAPTCHA once and reuse the session to bypass the check on subsequent requests.
Affects Plugins
References
Miscellaneous
Original Researcher
David Marín
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-05-08 (about 3 months ago)
Added
2026-05-12 (about 3 months ago)
Last Updated
2026-05-12 (about 3 months ago)