PT-2026-68877 · WordPress · Simple Captcha With Cloudflare Turnstile
CVE-2026-15239
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple CAPTCHA with Cloudflare Turnstile versions prior to 1.42.0
Description
In the Forminator integration, the plugin fails to bind the Turnstile validation cache to the single-use challenge token. Instead, it uses a reusable request value that can be controlled by an attacker. This allows unauthenticated users to solve a single challenge and subsequently replay form submissions without a token for a limited time, bypassing the anti-abuse protection.
Recommendations
Update Simple CAPTCHA with Cloudflare Turnstile to version 1.42.0 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Captcha With Cloudflare Turnstile