Impact
The Contact Form 7 WordPress plugin before version 2.5 fails to validate the host of a user‑supplied return URL that is used as the success and cancel redirect targets in a Stripe checkout flow. An unauthenticated attacker can embed a malicious return URL in a crafted link, leading a user who completes a purchase to an arbitrary external site after the checkout session. The primary security impact is an open redirect that can facilitate phishing or other social‑engineering attacks.
Affected Systems
Any WordPress site that has the Contact Form 7 plugin installed with the PayPal & Stripe add‑on and is running a version older than 2.5 is potentially vulnerable. Sites that have updated to 2.5 or later are not affected. The vulnerability does not involve other plugins or core WordPress components.
Risk and Exploitability
The CVSS score of 4.7 places this issue in the low‑moderate range, and it is not listed in the CISA KEV catalog. The EPSS score is < 1% (0.00171), indicating a low probability of exploitation, but the attack is straightforward: an attacker posts a link containing a forged return URL, and an unauthenticated user who clicks it will be redirected after checkout. As the flaw is web driven and does not require user credentials, the likelihood of exploitation in the wild exists but is likely limited to targeted phishing campaigns that benefit from the checkout surface.
OpenCVE Enrichment