PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91010 Invisible Anti‑Spam & CAPTCHA — reCAPTCHA Alternative for All Forms CVE debrief

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to permanently delete every form submission the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 has stored.

Vendor
Invisible Anti‑Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
Product
Invisible Anti‑Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders who manage WordPress installations with the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin should assess their exposure and prioritize verification of the plugin version and user role capabilities.

Why it matters

The CVE-2026-91010 vulnerability in the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin allows any authenticated user to permanently delete form submissions, potentially impacting data integrity and availability.

  • Defenders need to verify the plugin version to prevent unauthorized deletion of form submissions.
  • Defenders should review user roles to ensure only authorized users can delete form submissions.
  • Defenders should monitor for suspicious activity related to form submissions.

Technical summary

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, allowing any authenticated user to permanently delete every form submission. This vulnerability can be exploited by an attacker to delete form submissions, potentially impacting data integrity and availability. Defenders should prioritize verifying the version of the plugin and ensuring it is updated to 5.1.1 or later. They should also review their current user roles and ensure that only authorized users have the capability to delete form submissions.

Defensive priority

Defenders should prioritize verifying the version of the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin and ensuring it is updated to 5.1.1 or later. They should also review their current user roles and ensure that only authorized users have the capability to delete form submissions.

Recommended defensive actions

  • Verify the version of the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin and update to 5.1.1 or later
  • Review current user roles and ensure only authorized users have the capability to delete form submissions
  • Monitor for any suspicious activity related to form submissions
  • Perform a thorough review of the plugin's configuration and settings to prevent unauthorized access
  • Implement additional monitoring and logging to detect potential security incidents
  • Conduct a thorough risk assessment to identify potential vulnerabilities and prioritize remediation
  • Review and update incident response plans to ensure readiness in case of a security breach

Evidence notes

The CVE record and NVD vulnerability detail page provide information about the vulnerability, but the evidence is limited. The source reference from WPScan provides additional context about the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91010 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91010

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91010 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91010

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.