Description
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to permanently delete every form submission the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 has stored.
Published: 2026-09-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Deletion of Form Submissions
Action: Apply Patch
AI Analysis

Impact

The Invisible Anti‑Spam & CAPTCHA plugin fails to verify a user’s capabilities when processing its message deletion AJAX action. The plugin merely checks for the presence of a nonce, which is insufficient for authentication, allowing any logged‑in user—including subscribers—to permanently delete every form submission stored by the plugin. This flaw directly results in loss of data, compromising the integrity of form submissions collected on the site.

Affected Systems

Any WordPress site running the Invisible Anti‑Spam & CAPTCHA – reCAPTCHA Alternative for All Forms plugin prior to version 5.1.1 is vulnerable. The issue applies to all installations where the plugin is active and users can submit forms, regardless of the site’s theme or additional plugins.

Risk and Exploitability

With a CVSS score of 4.3, the vulnerability is considered moderate. The EPSS score of less than 1% indicates a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the deletion action can be exercised by any authenticated user, an attacker with a subscriber account could exploit the flaw by sending a crafted AJAX request to the plugin’s deletion endpoint, resulting in wholesale removal of stored form submissions.

Generated by OpenCVE AI on September 18, 2026 at 04:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the plugin to version 5.1.1 or later, which includes proper capability checks for the deletion action.
  • If the plugin is not necessary for your site’s functionality, uninstall it entirely to eliminate the vulnerable code path.
  • Implement additional access control by configuring your WordPress firewall or security plugin to block or restrict AJAX requests to the plugin’s deletion endpoint for non‑administrator user roles.

Generated by OpenCVE AI on September 18, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to permanently delete every form submission the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 has stored.
Title Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:26:27.198Z

Reserved: 2026-09-14T16:12:38.081Z

Link: CVE-2026-91010

cve-icon Vulnrichment

Updated: 2026-09-17T12:09:52.226Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:52.750

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-91010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses