What is CVE-2026-16146?
This CVE identifies a SQL Injection vulnerability in the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" plugin for WordPress, affecting versions up to and including 5.1. The flaw stems from insufficient escaping of user-supplied parameters via Pattern JSON keys/values and a lack of proper query preparation. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: Bu CVE, WordPress üçün "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" (versiya 5.1 və əvvəlki) plaginində aşkarlanmış SQL Injection zəifliyidir. Pattern JSON açar/dəyərləri vasitəsilə istifadəçi tərəfindən ötürülən parametrlərin düzgün filtirlənməməsi və sorğuların yetərsiz hazırlanması səbəbindən yaranır. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-16146?
This vulnerability affects the "Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms" plugin, version 5.1 and earlier.
What is the root cause of CVE-2026-16146?
The root cause is a SQL Injection vulnerability resulting from insufficient escaping of user-supplied parameters via Pattern JSON keys/values and a lack of proper query preparation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.