VYPR

Simple CAPTCHA with Cloudflare Turnstile

by WordPress

CVEs (2)

  • CVE-2026-85116MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on…

  • CVE-2026-15239MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated…