CVE-2026-16094: Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via 'key' Parameter
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16094?
CVE-2026-16094 has a medium severity rating of 4.9.
What type of vulnerability is CVE-2026-16094?
CVE-2026-16094 is an SQL Injection vulnerability.
How can CVE-2026-16094 affect my website?
CVE-2026-16094 can allow attackers to execute unauthorized SQL commands on your database.
How do I fix CVE-2026-16094?
To fix CVE-2026-16094, update the Invisible Anti-Spam & CAPTCHA plugin to a version later than 5.1.
Who is affected by CVE-2026-16094?
Any WordPress site using versions of the Invisible Anti-Spam & CAPTCHA plugin up to and including 5.1 is at risk from CVE-2026-16094.