Impact
The vulnerability arises when the ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 plugin allows insertion of sensitive information into data that is sent to the server or external services. This flaw permits an attacker to retrieve embedded sensitive data, such as payment credentials or credit card information, thereby compromising confidentiality. The weakness is categorized as Data Exposure (CWE-201).
Affected Systems
WordPress sites using the ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 plugin version 2.5 or earlier are affected. The plugin integrates with the Contact Form 7 plugin to process payment information.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is remote, where an adversary could submit crafted form data or intercept network traffic between the site and the payment processor, enabling them to extract sensitive data. Based on the description, it is inferred that the flaw could be triggered by any user who can submit a form that includes Authorize.NET payment details.
OpenCVE Enrichment
EUVD