CVE-2026-66674: WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability
Published Sep 10, 2026
·Updated
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
Affected Software
1 affected component
WordPress Simple Cloudflare Turnstile<=1.42.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simple Cloudflare Turnstileto a version that resolves this vulnerability.Fixed in 1.42.3
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The affected version range is Simple Cloudflare Turnstile 1.42.1 and earlier. The provided information does not identify any configuration-specific limitation.
2
Does exploitation require an authenticated WordPress account or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with no privileges required and no user interaction required, although attack complexity is rated high.