Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-40799 2 Replywp, Wordpress 2 Simple Cloudfare Turnstile, Wordpress 2026-06-26 5.8 Medium
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
CVE-2023-5135 1 Replywp 1 Simple Cloudfare Turnstile 2026-04-08 6.4 Medium
The Simple Cloudflare Turnstile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gravity-simple-turnstile' shortcode in versions up to, and including, 1.23.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.