Exposure in Simple CAPTCHA Plugin for WordPress by Cloudflare
CVE-2026-15239
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 August 2026
Badges
What is CVE-2026-15239?
The Simple CAPTCHA with Cloudflare Turnstile plugin for WordPress prior to version 1.42.0 is vulnerable to an improper token validation issue. The plugin fails to properly bind its Turnstile validation cache to the unique challenge token in its Forminator integration. This oversight allows attackers to exploit a reusable request value, enabling unauthenticated users to solve a single challenge and subsequently replay token-less submissions for a limited duration. This vulnerability undermines the plugin's intended anti-abuse protection measures, making it critical for site owners to update to the latest version.
Affected Version(s)
Simple CAPTCHA with Cloudflare Turnstile 0 < 1.42.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved