CVE · Medium

CVE-2026-40799 — Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.38.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-40799 Simple CAPTCHA with Cloudflare Turnstile [simple-cloudflare-turnstile] < 1.38.1 Authentication Bypass Using an Alternate Path or Channel Medium 5.8 < 1.38.1 1.38.1 2026-05-08

CVE-2026-40799

The Simple Cloudflare Turnstile plugin for WordPress, versions up to and including 1.38.0, contains a security flaw that allows unauthorized access due to inadequate authentication controls. This vulnerability was addressed in version 1.38.1 of the plugin. Users are advised to update their installations to the latest patched version to prevent potential exploitation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.