CVE-2026-91010: CWE-862 Missing Authorization in Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before version 5.1.1 contains a missing authorization vulnerability in its message deletion AJAX action. The plugin fails to properly check user capabilities and only verifies the presence of a nonce parameter without validating it. This flaw allows any authenticated user, including low-privileged roles such as subscribers, to permanently delete all stored form submissions.
AI Analysis
Technical Summary
CVE-2026-91010 is a missing authorization vulnerability (CWE-862) in the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin versions 2.0.5 up to but not including 5.1.1. The plugin's AJAX action for deleting messages does not properly verify the user's permissions and only checks for the presence of a nonce parameter without validating it. As a result, any authenticated user can exploit this flaw to delete every form submission stored by the plugin.
Potential Impact
An attacker with any authenticated user account, including low-privileged roles such as subscribers, can permanently delete all form submissions stored by the plugin. This could result in loss of important data collected through forms, impacting site functionality and data integrity.
Mitigation Recommendations
Upgrade the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin to version 5.1.1 or later, where this authorization issue is fixed. Until then, restrict user roles that can authenticate on the site to trusted users only.
CVE-2026-91010: CWE-862 Missing Authorization in Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
Description
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before version 5.1.1 contains a missing authorization vulnerability in its message deletion AJAX action. The plugin fails to properly check user capabilities and only verifies the presence of a nonce parameter without validating it. This flaw allows any authenticated user, including low-privileged roles such as subscribers, to permanently delete all stored form submissions.
Affected software
Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-91010 is a missing authorization vulnerability (CWE-862) in the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin versions 2.0.5 up to but not including 5.1.1. The plugin's AJAX action for deleting messages does not properly verify the user's permissions and only checks for the presence of a nonce parameter without validating it. As a result, any authenticated user can exploit this flaw to delete every form submission stored by the plugin.
Potential Impact
An attacker with any authenticated user account, including low-privileged roles such as subscribers, can permanently delete all form submissions stored by the plugin. This could result in loss of important data collected through forms, impacting site functionality and data integrity.
Mitigation Recommendations
Upgrade the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin to version 5.1.1 or later, where this authorization issue is fixed. Until then, restrict user roles that can authenticate on the site to trusted users only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-14T16:12:38.081Z
- State
- PUBLISHED
Threat ID: 6aab827755bf5e2cf5d4d336
Added to database: 09/17/2026, 06:02:31 UTC
Last enriched: 09/17/2026, 06:16:48 UTC
Last updated: 09/17/2026, 06:21:31 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.