CVE-2026-105990 PUBLISHED

Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via CSV Export

Assigner: WPScan
Reserved: 06.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.

Product Status

Vendor Unknown
Product Accept PayPal Payments using Contact Form 7
Versions Default: unaffected
  • affected from 0 to 4.0.7 (excl.)

Credits

  • Enrico Marcolini finder
  • Claudio Marchesini finder
  • Dottor Marc finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE