PT-2026-68877 · WordPress · Simple Captcha With Cloudflare Turnstile

CVE-2026-15239

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Simple CAPTCHA with Cloudflare Turnstile versions prior to 1.42.0
Description In the Forminator integration, the plugin fails to bind the Turnstile validation cache to the single-use challenge token. Instead, it uses a reusable request value that can be controlled by an attacker. This allows unauthenticated users to solve a single challenge and subsequently replay form submissions without a token for a limited time, bypassing the anti-abuse protection.
Recommendations Update Simple CAPTCHA with Cloudflare Turnstile to version 1.42.0 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15239

Affected Products

Simple Captcha With Cloudflare Turnstile