Message Deletion Vulnerability in Invisible Anti-Spam & CAPTCHA WordPress Plugin
CVE-2026-91010
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2026
Badges
What is CVE-2026-91010?
The Invisible Anti-Spam & CAPTCHA plugin for WordPress prior to version 5.1.1 lacks proper validation for user capabilities during the AJAX action for message deletion. This oversight allows any authenticated user, including those with the lowest permission levels, to delete all stored form submissions without adequate checks. The vulnerability arises because the plugin only verifies the presence of a nonce parameter instead of performing a thorough capability validation, posing a significant risk to data integrity and management within the affected WordPress installations.
Affected Version(s)
Invisible Anti-Spam & CAPTCHA β reCAPTCHA Alternative for All Forms 2.0.5 < 5.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.