Description
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
Published: 2026-06-15
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Simple Cloudflare Turnstile plugin contains a broken authentication flaw that permits unauthenticated users to access privileged functions of the WordPress site. The vulnerability is classified as CWE‑288, indicating an authentication failure that can raise the privilege level of an attacker. Based on the description, this could allow an attacker to authenticate as an administrative user without valid credentials, exposing the site to potential misuse of the administrator account.

Affected Systems

The flaw affects the RelyWP Simple Cloudflare Turnstile plugin, specifically versions up to and including 1.38.0. The vulnerability does not extend to newer releases or to WordPress installations that do not use this plugin.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate risk. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated web request to the plugin’s authentication endpoint, which does not require prior user credentials.

Generated by OpenCVE AI on June 16, 2026 at 23:20 UTC.

Remediation

Vendor Solution

Update the WordPress Simple Cloudflare Turnstile Plugin to the latest available version (at least 1.38.1).


OpenCVE Recommended Actions

  • Update the Simple Cloudflare Turnstile plugin to version 1.38.1 or later
  • If an update cannot be applied immediately, disable or remove the plugin from the WordPress installation to eliminate the exposed entry point
  • Consider implementing network or application-layer controls to block unauthenticated requests to the plugin’s authentication endpoint until the update is applied

Generated by OpenCVE AI on June 16, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
Title WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-15T22:29:31.629Z

Reserved: 2026-04-15T09:20:46.957Z

Link: CVE-2026-40799

cve-icon Vulnrichment

Updated: 2026-06-15T22:29:27.866Z

cve-icon NVD

Status : Deferred

Published: 2026-06-15T21:16:52.253

Modified: 2026-06-15T21:24:32.790

Link: CVE-2026-40799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:30:15Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel