Description
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin receives a Turnstile challenge token for each form submission but incorrectly stores the response cache based on a reusable request value instead of the one‑time challenge token. This oversight lets an unauthenticated attacker solve a single challenge and then replay the validated result for multiple subsequent form submissions within a short period, effectively bypassing the anti‑abuse protection.

Affected Systems

All installations of the Simple CAPTCHA with Cloudflare Turnstile WordPress plugin with a version number earlier than 1.42.0. The vulnerability specifically impacts the Forminator integration of the plugin.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. Because the exploit requires only the ability to submit a form, Internet‑connected attackers can exploit this flaw without prior authentication. The EPSS score is 0.00111, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, yet the attacker's method is straightforward and therefore substantial risk remains.

Generated by OpenCVE AI on August 7, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Simple CAPTCHA with Cloudflare Turnstile plugin to version 1.42.0 or later
  • Temporarily disable or restrict form submissions that rely on Forminator integration until the plugin is upgraded
  • Enforce proper binding of the Turnstile challenge to each form submission to prevent replay attacks
  • Check for updates to WordPress core and the Forminator plugin, applying security patches promptly

Generated by OpenCVE AI on August 7, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Simple Captcha
Simple Captcha simple Captcha With Cloudflare Turnstile
Wordpress
Wordpress wordpress
Vendors & Products Simple Captcha
Simple Captcha simple Captcha With Cloudflare Turnstile
Wordpress
Wordpress wordpress

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
CWE-785

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.
Title Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Simple Captcha Simple Captcha With Cloudflare Turnstile
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T15:19:13.952Z

Reserved: 2026-07-09T11:43:59.002Z

Link: CVE-2026-15239

cve-icon Vulnrichment

Updated: 2026-08-07T15:19:06.901Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T08:16:45.897

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-15239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:23Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-785

    Use of Path Manipulation Function without Maximum-sized Buffer