VYPR

Simple CAPTCHA with Cloudflare Turnstile

by WordPress

CVEs (1)

  • CVE-2026-15239MedAug 7, 2026
    risk 0.34cvss 5.3epss

    The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated…