Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile Plugin by WordPress
CVE-2026-66674

5.6MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 September 2026

What is CVE-2026-66674?

An unauthenticated bypass vulnerability has been identified in the Simple Cloudflare Turnstile plugin for WordPress, affecting versions up to 1.42.1. This security flaw allows unauthorized users to circumvent intended restrictions, potentially leading to unauthorized access or abuse of the plugin's features. It is crucial for WordPress site administrators to monitor and update their plugins regularly to mitigate risks associated with this security issue.

Affected Version(s)

Simple Cloudflare Turnstile <= 1.42.1

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.