CyberRota Analysis
AI-GeneratedThe Simple CAPTCHA with Cloudflare Turnstile WordPress plugin prior to version 1.42.0 is vulnerable due to improper binding of its Turnstile validation cache, allowing unauthenticated attackers to exploit a reusable request value. This flaw enables attackers to bypass anti-abuse protections by replaying token-less form submissions after solving a challenge. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of abuse.
Original NVD Description
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.