Common Cloudflare Turnstile Errors in WordPress Forms (And How to Fix Them)

Cloudflare Turnstile homepage

Cloudflare Turnstile is a user-friendly, privacy-first CAPTCHA alternative that’s becoming popular with WordPress users. But it can run into issues, especially with form plugins. This guide covers common Turnstile errors in WordPress forms and how to fix them fast.

đź’ˇ Tired of fixing Turnstile errors? oopspam stops spam on your server, with no widget for visitors, no challenge script, and no tokens to expire. See our Cloudflare Turnstile alternative for WordPress.

Why Cloudflare Turnstile errors happen in WordPress

Turnstile issues usually come down to misconfigurations, plugin conflicts, browser-related problems, or expired credentials. WordPress adds complexity due to its wide variety of themes, plugins, and caching systems, all of which can interfere with how Turnstile renders or validates.

We’ve seen several recurring errors across forums, especially from form users. Let’s go over them one by one.

1. “Cloudflare Turnstile verification failed, please try again later.”

Cloudflare Turnstile verification failed, please try again later.

This is one of the most common Turnstile error messages in WordPress. It often appears after submitting a form.

Cause:

This usually happens when the Site Key or Secret Key entered is incorrect. Another common reason is interference from caching plugins like Breeze or WP Rocket, which may prevent Turnstile from loading properly. Sometimes, the issue stems from browser cache or extensions that block necessary scripts.

How to Fix:

Double-check your Site Key and Secret Key in the Turnstile plugin settings.

2. Turnstile Widget Not Displaying on Form

Turnstile Widget Not Displaying on Form

Sometimes, the Turnstile CAPTCHA box doesn’t appear at all.

Cause:

The Turnstile widget won’t appear if JavaScript is disabled in the browser. Conflicts between your theme or other plugins may prevent it from rendering. In some cases, minified or combined scripts break the Turnstile widget’s ability to load correctly.

How to Fix:

3. Form Submission Blocked Even After Passing Turnstile

A particularly frustrating issue is when users solve the Turnstile challenge, but the form doesn’t submit.

Affected Plugins:

This issue can happen with any WordPress form builder, but we’ve seen the most reports from users of: 

Cause:

AJAX-based form submissions sometimes bypass the Turnstile verification token. File upload fields in forms, especially in Forminator, can also interfere with how the plugin processes verification. Some plugins may also skip server-side token validation entirely.

How to Fix:

4. Error 110200: “Domain not authorized”

"Invalid domain" Cloudflare Turnstile Errors

Error codes:

Cause:

Turnstile only runs on hostnames you’ve added to the widget. The page showing your form is on a hostname the widget doesn’t list. Common reasons in WordPress:

How to fix:

  1. In the Cloudflare dashboard, open Turnstile, select the widget whose site key your plugin uses, then go to Settings > Hostname Management and select Add Hostnames.
  2. Add the root domain (for example example.com). Enter the hostname only: no https://, port, path or wildcard.
  3. Save, then reload the form page with the cache cleared.
  4. If the hostname is already listed and the error continues, remove it and add it again. That fixed it for this Cloudflare community user.
  5. For localhost or local development, use Cloudflare’s test site keys, which work on any domain, instead of adding local domains to your production widget.

Free Cloudflare plans allow up to 10 hostnames per widget, so if you run many sites, use one widget per group of sites.

5. Error 110100 / 400020: “Invalid sitekey”

Error codes:

How to fix:

6. Error 110110: “Sitekey not found”

Error codes:

How to fix:

7. Error 400070: “Sitekey disabled”

Error codes:

How to fix:

8. Error 400021: “Sitekey domain mismatch”

Error codes:

How to fix:

9. Error 110600: “Challenge timed out”

Turnstile Challenge Timeout

Error codes:

Cause:

The challenge took too long to complete, or the visitor’s device clock is wrong.

How to fix:

10. Error 110620: “Interaction timed out”

Error codes:

Cause:

The visitor didn’t interact with the widget in time, for example by leaving the form open in a tab and coming back later.

How to fix:

11. Error 200100: “Clock or cache problem”

Error codes:

Cause:

Either the visitor’s clock is wrong, or something between the visitor and Cloudflare cached the challenge. On WordPress, that’s usually a page cache or CDN serving an old copy of the form page.

How to fix:

12. Error 200500: “Iframe load error”

Error codes:

Cause:

The Turnstile iframe couldn’t load, usually because challenges.cloudflare.com is blocked.

How to fix:

13. Error 110420: “Invalid action”

Error codes:

How to fix:

14. Error 110430: “Invalid cData”

Error codes:

How to fix:

These two codes aren’t in Cloudflare’s current error code table, but they still appear in older integrations and forum threads.

15. Cloudflare Turnstile error code 106010 {#7-cloudflare-turnstile-error-code-106010}

Cloudflare Turnstile error code 106010

Error Codes:

106010 isn’t in Cloudflare’s current error code table, but it’s one of the most searched Turnstile errors. In WordPress it usually appears when something about the page environment or the widget’s parameters isn’t accepted.

Common WordPress level causes to check

How to fix

16. “Turnstile token missing” {#8-turnstile-token-missing}

Turnstile token missing

Common query:

Turnstile automatically injects a hidden input named cf-turnstile-responseinside a form. That input carries the token that your server should validate. If that field is missing, empty, or not included in the request, Siteverify can return errors like missing-input-response.

Most likely causes

How to fix

Cloudflare documents these Siteverify response errors, which map directly to real WordPress issues:

This error occurs when a form submission reaches the server without a Turnstile response token attached.

17. Client-Side Execution Errors (300010, 300030, 300031) {#9-client-side-execution-errors-300010-300030-300031}

Client-Side Execution Errors (300010, 300030, 300031)

Error Codes:

Cloudflare lists 300* as a generic challenge failure: Turnstile detected bot-like behavior. Real visitors usually hit it when the widget can’t complete its front-end flow, because scripts are delayed, blocked or rewritten.

How to fix

Retrying may work temporarily, but persistent errors point to browser or script-loading issues.

18. Challenge Execution Failure (600010) {#10-challenge-execution-failure-600010}

Challenge Execution Failure (600010)

Error Codes:

Cloudflare also lists 600* as a generic challenge failure: bot-like behavior was detected. In the Cloudflare community, 600010 is often discussed alongside browser state, extensions and network blockers.

How to fix

This error is expected behavior when Turnstile detects abnormal execution conditions.

Technical Turnstile Error Codes and What They Mean

These are the codes Cloudflare currently documents. They show up in the browser console or in your form plugin’s error message:

Error code Cloudflare's description Retry Fix
110100 Invalid sitekey No Copy the site key again from the dashboard
110110 Sitekey not found No Check spelling; confirm the widget exists
110200 Domain not authorized No Add the domain in Hostname Management
110600 Challenge timed out Yes Refresh; check the device clock
110620 Interaction timed out Yes Reset the widget with turnstile.reset()
200100 Clock or cache problem No Exclude form pages from cache; check the clock
200500 Iframe load error Yes Unblock challenges.cloudflare.com
300* Generic challenge failure Yes Check scripts, extensions, VPNs
400020 Invalid sitekey No Copy the site key again from the dashboard
400021 Sitekey domain mismatch No Load the script tag exactly as documented
400070 Sitekey disabled No Re-enable the widget or create a new one
600* Generic challenge failure Yes Check scripts, extensions, VPNs

Source: Cloudflare’s Turnstile error codes, checked 8 October 2026. A * means the remaining digits vary. Codes like 106010, 110420 and 110430 aren’t in the current table; see their sections above.

Use oopspam for Advanced Spam Filtering

Turnstile helps reduce automated form abuse, but it is not the whole solution. Some spam still gets through, and some attacks focus on content quality rather than pure automation.

oopspam WordPress plugin (that’s us 👋) adds a second layer that helps catch nuisance submissions, patterns, and language based abuse, without adding more friction for real users.

oopspam WordPress plugin

Benefits of using oopspam:

Turnstile alternative solutions like oopspam gives you layered protection without overburdening your users.

Final Thoughts

Most Cloudflare Turnstile issues in WordPress come down to configuration, script loading, or token handling. Once keys are verified, caching is controlled, and server-side validation is confirmed, most errors resolve quickly.

For stronger protection and fewer false positives, combining Turnstile with background spam filtering provides a more reliable approach without hurting user experience. Whether you’re already using Turnstile or just exploring spam protection options, it’s a great time to get started with oopspam for advanced, frictionless form security.

Stay secure and spam-free!

Spam Protection for WordPress, Zapier, Make and more.

Since our launch in 2017 we’ve been perfecting our API to be the trusted option for small businesses to enterprise— and continue to stick to our values of being the accessibility and privacy-friendly option. Give us a shot!

Try oopspam for free → Try our WordPress plugin for free →

âś“ No credit card required âś“ Cancel anytime

Enjoy Reading This Article?

Here are some more articles you might like to read next: