Vulnerabilities and security researches forsimple-cloudflare-turnstile simple-cloudflare-turnstile
Direction: descendingSep 25, 2026
Simple Cloudflare Turnstile – CAPTCHA Alternative # PSC-2026-65708
- PSC, Research URL
- Date
- Sep 25, 2026
- Research Description
- Anti-spam integrations accept challenge tokens on public forms and exchange them with an external verification service before a submission is allowed. Simple CAPTCHA with Cloudflare Turnstile version 1.43.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65708. The review focused on settings permissions, key handling, challenge token validation, server side verification, form integration, whitelisting, failsafe behavior, and diagnostic logging.
- Affected versions
-
Min 1.43.2, max 1.43.2.
- Status
-
SAFE & CERTIFIED
Sep 11, 2026
Simple Cloudflare Turnstile – CAPTCHA Alternative # CVE-2026-66674
- CVE, Research URL
- Date
- Sep 10, 2026
- Research Description
- Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
- Affected versions
-
max 1.42.3.
- Status
-
vulnerable
Simple Cloudflare Turnstile – CAPTCHA Alternative # CVE-2026-66632
- CVE, Research URL
- Date
- Sep 10, 2026
- Research Description
- Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.
- Affected versions
-
max 1.42.3.
- Status
-
vulnerable
Aug 09, 2026
Simple Cloudflare Turnstile – CAPTCHA Alternative # CVE-2026-15239
- CVE, Research URL
- Date
- Aug 07, 2026
- Research Description
- The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.
- Affected versions
-
max 1.42.0.
- Status
-
vulnerable
May 12, 2026
Simple Cloudflare Turnstile – CAPTCHA Alternative # CVE-2026-40799
- CVE, Research URL
- Date
- Jun 16, 2026
- Research Description
- Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
- Affected versions
-
max 1.38.1.
- Status
-
vulnerable
Jun 06, 2024
Simple Cloudflare Turnstile – CAPTCHA Alternative # CVE-2023-5135
- CVE, Research URL
- Date
- Sep 27, 2023
- Research Description
- The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-turnstile' shortcode in versions up to, and including, 1.23.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.23.2.
- Status
-
vulnerable