WordPress Plugin Vulnerabilities
Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key
Description
The plugin does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-03 (about 26 days ago)
Added
2026-08-03 (about 26 days ago)
Last Updated
2026-08-03 (about 26 days ago)