What is CVE-2026-16094?
This vulnerability exists in the 'Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms' plugin for WordPress. It allows remote SQL Injection via the 'key' parameter due to insufficient input escaping. Site owners should temporarily disable the plugin or restrict the 'key' input points via Web Application Firewall rules until a security patch is released.
Azərbaycanca: Bu boşluq sözdə «The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms» adlı WordPress plaqinində tapılıb. 'key' parametrindəki yetərsiz təmizləmə səbəbindən uzaqdan SQL Injection hücumuna imkan verir. Sayt sahibləri plaqinin təhlükəsizlik yaması çıxana qədər onu müvəqqəti olaraq söndürməli və ya 'key' daxiletmə nöqtələrini Web Application Firewall qaydaları ilə məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: WordPress
FAQ2
In which WordPress plugin was CVE-2026-16094 discovered?
This vulnerability was found in the 'Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms' plugin.
What temporary measure is recommended for site owners until a security patch is released?
Site owners are advised to temporarily disable the plugin or restrict the 'key' input points via Web Application Firewall rules.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.