CVE-2026-15239: CWE-345 Insufficient Verification of Data Authenticity in Simple CAPTCHA with Cloudflare Turnstile
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin versions prior to 1.42.0 contains a vulnerability where its Turnstile validation cache is not properly bound to the single-use challenge token. This allows unauthenticated attackers to solve one CAPTCHA challenge and then replay token-less form submissions within a short time window, bypassing the anti-abuse protection. The vulnerability is identified as CWE-345: Insufficient Verification of Data Authenticity. A patch is available to address this issue.
AI Analysis
Technical Summary
CVE-2026-15239 affects the Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before version 1.42.0. The vulnerability arises because the plugin's Forminator integration keys its Turnstile validation cache to an attacker-controlled, reusable request value instead of the single-use challenge token. This flaw enables unauthenticated attackers to bypass CAPTCHA protections by replaying form submissions without valid tokens after solving a single challenge. The issue is categorized under CWE-345, indicating insufficient verification of data authenticity. The vulnerability has a CVSS 3.1 base score of 5.3 (medium severity). The plugin is a cloud service, and a patch is available to fix the issue.
Potential Impact
Attackers can bypass the CAPTCHA anti-abuse mechanism by reusing a solved challenge token to submit multiple token-less form submissions. This undermines the intended protection against automated abuse or spam on forms using the affected plugin. There is no direct confidentiality or availability impact reported, but the integrity of form submission validation is compromised.
Mitigation Recommendations
A patch is available for Simple CAPTCHA with Cloudflare Turnstile plugin version 1.42.0 and later that fixes this vulnerability. Users should upgrade to version 1.42.0 or newer to remediate the issue. Since this is a cloud service plugin, the vendor manages remediation for the cloud-hosted service. Check the vendor advisory for confirmation and apply the official update promptly.
CVE-2026-15239: CWE-345 Insufficient Verification of Data Authenticity in Simple CAPTCHA with Cloudflare Turnstile
Description
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin versions prior to 1.42.0 contains a vulnerability where its Turnstile validation cache is not properly bound to the single-use challenge token. This allows unauthenticated attackers to solve one CAPTCHA challenge and then replay token-less form submissions within a short time window, bypassing the anti-abuse protection. The vulnerability is identified as CWE-345: Insufficient Verification of Data Authenticity. A patch is available to address this issue.
CVSS v3.1
Score 5.3medium
Affected software
Simple CAPTCHA with Cloudflare Turnstile
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15239 affects the Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before version 1.42.0. The vulnerability arises because the plugin's Forminator integration keys its Turnstile validation cache to an attacker-controlled, reusable request value instead of the single-use challenge token. This flaw enables unauthenticated attackers to bypass CAPTCHA protections by replaying form submissions without valid tokens after solving a single challenge. The issue is categorized under CWE-345, indicating insufficient verification of data authenticity. The vulnerability has a CVSS 3.1 base score of 5.3 (medium severity). The plugin is a cloud service, and a patch is available to fix the issue.
Potential Impact
Attackers can bypass the CAPTCHA anti-abuse mechanism by reusing a solved challenge token to submit multiple token-less form submissions. This undermines the intended protection against automated abuse or spam on forms using the affected plugin. There is no direct confidentiality or availability impact reported, but the integrity of form submission validation is compromised.
Mitigation Recommendations
A patch is available for Simple CAPTCHA with Cloudflare Turnstile plugin version 1.42.0 and later that fixes this vulnerability. Users should upgrade to version 1.42.0 or newer to remediate the issue. Since this is a cloud service plugin, the vendor manages remediation for the cloud-hosted service. Check the vendor advisory for confirmation and apply the official update promptly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-09T11:43:59.002Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6a758c3ebf8831d539f76881
Added to database: 08/07/2026, 07:41:50 UTC
Last enriched: 08/14/2026, 16:13:04 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 80
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.