---
id: CVE-2026-91010
title: >-
  The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
  WordPress plugin before 5.1.1 does not check the user's capabilities in its
  message deletion AJAX action, and only tests that a nonce parameter is present
  rather tha…
summary: >-
  The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
  WordPress plugin before 5.1.1 does not check the user's capabilities in its
  message deletion AJAX action, and only tests that a nonce parameter is present
  rather tha…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
affected:
  - >-
    invisible_anti-spam_captcha_recaptcha_alternative_for_all_forms >= 2.0.5 <
    5.1.1
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91010'
references:
  - url: 'https://wpscan.com/vulnerability/08860091-c3e4-43f1-b2e2-82fb8d45a5fa/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00152
epssPercentile: 0.04744
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:10:50.936743Z'
ingestedAt: '2026-09-17T06:12:17.971Z'
---

## Overview

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to permanently delete every form submission the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 has stored.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
