CVE-2026-105989
Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status Forgery
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.
| Vendor | unknown |
| Product | accept paypal payments using contact form 7 |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown accept paypal payments using contact form 7
Be the first to know when new unknown vulnerabilities affecting unknown accept paypal payments using contact form 7 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Accept PayPal Payments using Contact Form 7
0 < 4.0.7
References
Credits
Daniel Dhaniswara WPScan