Impact
This flaw permits an unauthenticated attacker to circumvent the Simple Cloudflare Turnstile CAPTCHA, effectively disabling a primary defense against automated abuse on affected WordPress sites. The weakness, classified as CWE‑290, removes the verification step needed to confirm legitimate human interaction, allowing automated scripts to submit forms, potentially leading to spam, credential stuffing, or other unwanted automated actions. While it does not provide code execution or direct data access, the loss of the CAPTCHA check undermines the integrity of user input and can degrade the overall security posture of the site.
Affected Systems
The vulnerability is present in the WordPress plugin Simple Cloudflare Turnstile from RelyWP for all versions up to and including 1.42.1. Any WordPress installation that relies on this plugin and has not upgraded to a newer version is potentially exposed.
Risk and Exploitability
With a CVSS score of 5.6 the issue carries moderate severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The flaw can be triggered by unauthenticated remote attackers using crafted HTTP requests against the plugin’s endpoints, making it likely to be exploited by automated campaigns.
OpenCVE Enrichment