Impact
The Simple Cloudflare Turnstile plugin contains a broken authentication flaw that permits unauthenticated users to access privileged functions of the WordPress site. The vulnerability is classified as CWE‑288, indicating an authentication failure that can raise the privilege level of an attacker. Based on the description, this could allow an attacker to authenticate as an administrative user without valid credentials, exposing the site to potential misuse of the administrator account.
Affected Systems
The flaw affects the RelyWP Simple Cloudflare Turnstile plugin, specifically versions up to and including 1.38.0. The vulnerability does not extend to newer releases or to WordPress installations that do not use this plugin.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate risk. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated web request to the plugin’s authentication endpoint, which does not require prior user credentials.
OpenCVE Enrichment