Message Deletion Vulnerability in Invisible Anti-Spam & CAPTCHA WordPress Plugin
CVE-2026-91010

Currently unrated

Key Information:

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-91010?

The Invisible Anti-Spam & CAPTCHA plugin for WordPress prior to version 5.1.1 lacks proper validation for user capabilities during the AJAX action for message deletion. This oversight allows any authenticated user, including those with the lowest permission levels, to delete all stored form submissions without adequate checks. The vulnerability arises because the plugin only verifies the presence of a nonce parameter instead of performing a thorough capability validation, posing a significant risk to data integrity and management within the affected WordPress installations.

Affected Version(s)

Invisible Anti-Spam & CAPTCHA β€” reCAPTCHA Alternative for All Forms 2.0.5 < 5.1.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

JunHee CHO
WPScan
.