What is CVE-2026-15239?
CVE-2026-15239 is a critical business logic flaw in the 'Simple CAPTCHA with Cloudflare Turnstile' WordPress plugin, allowing unauthenticated attackers to bypass CAPTCHA validation in the Forminator integration. This affects plugin versions prior to 1.42.0. Site administrators must immediately update to the latest version or temporarily disable the Forminator integration.
Azərbaycanca: CVE-2026-15239, "Simple CAPTCHA with Cloudflare Turnstile" WordPress plaginində autentifikasiya olunmamış hücumçulara CAPTCHA yoxlamasını keçməyə imkan verən kritik biznes məntiqi zəifliyidir. Bu problem plaginin 1.42.0 versiyasından əvvəlki versiyalarına təsir edir. Sayt administratorları dərhal plagini ən son versiyaya yeniləməli və ya müvəqqəti olaraq Forminator inteqrasiyasını deaktiv etməlidirlər.
Related CVEs
link basis: shared vendor: WordPress
FAQ2
Which WordPress plugin is affected by CVE-2026-15239?
CVE-2026-15239 affects the 'Simple CAPTCHA with Cloudflare Turnstile' plugin.
What should site administrators do to mitigate this vulnerability?
Site administrators must immediately update the plugin to version 1.42.0 or later, or temporarily disable the Forminator integration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.