Impact
The vulnerability is an insertion of sensitive information into sent data, allowing the retrieval of embedded sensitive data. This flaw falls under CWE-201, which covers the improper handling of confidential data. As a result, anyone who can trigger or observe the malformed responses may gain access to payment details or other confidential information, compromising confidentiality and potentially enabling fraud.
Affected Systems
The affected product is the ZealousWeb Accept Stripe Payments Using Contact Form 7 WordPress plugin, versions from the initial release up to and including 3.0. WordPress sites running any of these versions are susceptible and should consider upgrading or disabling the plugin.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves malicious or improperly formed HTTP requests that embed sensitive data into responses. An attacker would need network exposure to the site and the ability to capture inbound or outbound traffic to abuse this flaw.
OpenCVE Enrichment
EUVD