CVE-2026-15239: Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15239?
CVE-2026-15239 has a medium severity score of 5.3.
How do I fix CVE-2026-15239?
To fix CVE-2026-15239, update the Simple CAPTCHA with Cloudflare Turnstile plugin to version 1.42.0 or later.
What are the risks associated with CVE-2026-15239?
CVE-2026-15239 allows unauthenticated attackers to bypass Turnstile protection, which can lead to unauthorized access.
Is CVE-2026-15239 specific to a certain software version?
Yes, CVE-2026-15239 affects the Simple CAPTCHA with Cloudflare Turnstile plugin versions prior to 1.42.0.
What type of vulnerability is CVE-2026-15239?
CVE-2026-15239 is an unauthenticated Turnstile protection bypass vulnerability.