Executive brief
Simple Cloudflare Turnstile is a WordPress plugin that provides bot protection for websites using Cloudflare's verification service. An unauthenticated content injection vulnerability allows attackers to inject malicious content, advertisements, or scam links into web pages without requiring user credentials. This can compromise site reputation, redirect visitors to malicious sites, or distribute malware.
Technical details
The vulnerability is a content injection flaw (OWASP A3: Injection) in Simple Cloudflare Turnstile versions 1.42.1 and earlier. The plugin fails to properly sanitize or validate input, allowing unauthenticated attackers to inject arbitrary content into affected pages. No authentication is required to exploit this vulnerability, and the attack is network-accessible. Attackers can inject unwanted content such as advertisements, phishing links, or malware distribution code. The vulnerability has been patched in version 1.42.3 or later.
Affected products
- RelyWP Simple Cloudflare Turnstile <= 1.42.1
Timeline
- 2026-09-08: disclosed: Vulnerability reported to Patchstack
- 2026-09-08: patched: Patched in version 1.42.3