CVE-2026-105989 PUBLISHED

Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status Forgery

Assigner: WPScan
Reserved: 06.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.

Product Status

Vendor Unknown
Product Accept PayPal Payments using Contact Form 7
Versions Default: unaffected
  • affected from 0 to 4.0.7 (excl.)

Credits

  • Daniel Dhaniswara finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE