Impact
Unauthenticated Content Injection is present in WordPress Simple Cloudflare Turnstile Plugin versions 1.42.1 and earlier, allowing an attacker to inject arbitrary HTML or JavaScript into a site via the plugin’s input handling code. This vulnerability is identified as CWE-94 and can lead to cross‑site scripting that may compromise user data or the integrity of the website’s content.
Affected Systems
The vulnerability affects the WordPress Simple Cloudflare Turnstile plugin published by Elliot Sowers/RelyWP, specifically all releases up through version 1.42.1. Users running these versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 reflects medium severity, with an unavailability of EPSS indicating that exploitation probability data is not currently published, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated HTTP requests that target the plugin’s configuration or usage endpoints, and the lack of authentication requirement makes it trivially exploitable by anyone who can reach the affected site.
OpenCVE Enrichment