Impact
This issue is a Cross‑Site Request Forgery flaw that allows an attacker to cause a user to perform unwanted actions by submitting forged requests through the Pay with Contact Form 7 plugin. An attacker could potentially trick a logged‑in user into making a payment or changing settings that the user did not intend to perform. The vulnerability stems from a lack of CSRF protection, classified as CWE-352.
Affected Systems
All installations of the cmsMinds Pay with Contact Form 7 plugin up to and including version 1.0.4 are affected. WordPress sites that use this plugin for payment processing or contact form handling are at risk; no other WordPress components are implicated.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, meaning no confirmed active exploitation has been reported. Exploitation would typically require the victim to be authenticated to the site or possess a valid session, after which an attacker can load a malicious page that submits a forged request to perform the unwanted action.
OpenCVE Enrichment
EUVD