cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsimple-cloudflare-turnstile simple-cloudflare-turnstile

Direction: descending
Sep 25, 2026

Simple Cloudflare Turnstile – CAPTCHA Alternative # PSC-2026-65708

PSC, Research URL

PSC-2026-65708

Date
Sep 25, 2026
Research Description
Anti-spam integrations accept challenge tokens on public forms and exchange them with an external verification service before a submission is allowed. Simple CAPTCHA with Cloudflare Turnstile version 1.43.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65708. The review focused on settings permissions, key handling, challenge token validation, server side verification, form integration, whitelisting, failsafe behavior, and diagnostic logging.
Affected versions
Min 1.43.2, max 1.43.2.
Status
SAFE & CERTIFIED
Sep 11, 2026

Simple Cloudflare Turnstile – CAPTCHA Alternative # CVE-2026-66674

CVE, Research URL

CVE-2026-66674

Date
Sep 10, 2026
Research Description
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
Affected versions
max 1.42.3.
Status
vulnerable

Simple Cloudflare Turnstile &#8211; CAPTCHA Alternative # CVE-2026-66632

CVE, Research URL

CVE-2026-66632

Date
Sep 10, 2026
Research Description
Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.
Affected versions
max 1.42.3.
Status
vulnerable
Aug 09, 2026

Simple Cloudflare Turnstile &#8211; CAPTCHA Alternative # CVE-2026-15239

CVE, Research URL

CVE-2026-15239

Date
Aug 07, 2026
Research Description
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.
Affected versions
max 1.42.0.
Status
vulnerable
May 12, 2026

Simple Cloudflare Turnstile &#8211; CAPTCHA Alternative # CVE-2026-40799

CVE, Research URL

CVE-2026-40799

Date
Jun 16, 2026
Research Description
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
Affected versions
max 1.38.1.
Status
vulnerable
Jun 06, 2024

Simple Cloudflare Turnstile &#8211; CAPTCHA Alternative # CVE-2023-5135

CVE, Research URL

CVE-2023-5135

Date
Sep 27, 2023
Research Description
The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-turnstile' shortcode in versions up to, and including, 1.23.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.23.2.
Status
vulnerable