Junglewise Threat Intelligence

CVE-2026-66674: WordPress Simple Cloudflare Turnstile auth bypass

CVE-2026-66674 · Severity: medium · CVSS 5.6 · Published 2026-09-10

Technologies: RelyWP Simple Cloudflare Turnstile. Vendors: RelyWP.

Executive brief

Simple Cloudflare Turnstile is a WordPress plugin that provides bot protection for web forms using Cloudflare's CAPTCHA service. The plugin in versions 1.42.1 and earlier contains a vulnerability that allows attackers to bypass security verification checks without authentication, potentially enabling automated attacks or spam submissions on affected websites.

Technical details

The vulnerability is classified as an authentication bypass or insecure design flaw in the Simple Cloudflare Turnstile WordPress plugin (versions ≤ 1.42.1). The plugin fails to properly validate or enforce security checks, allowing unauthenticated attackers to circumvent the Cloudflare Turnstile CAPTCHA protection. This is a network-accessible vulnerability requiring no authentication, making it trivial to exploit. Attackers can bypass bot protection mechanisms, potentially automating form submissions, account creation, or other protected actions on vulnerable WordPress installations. The vulnerability was patched in version 1.42.3, and affected users should update immediately.

Affected products

  • RelyWP Simple Cloudflare Turnstile <=1.42.1

Timeline

  • 2026-09-08: disclosed: Vulnerability published by Patchstack
  • 2026-09-10: patched: Fix released in version 1.42.3

References

Related threats