Impact
The vulnerability is a missing authorization flaw in the ZealousWeb Accept PayPal Payments using Contact Form 7 plugin that allows users without the proper privileges to perform privileged actions. By bypassing the intended access control, an attacker could modify subscription plans, alter transaction amounts, or trigger unauthorized payments, directly compromising the financial integrity of the site.
Affected Systems
This flaw affects all releases of the ZealousWeb Accept PayPal Payments using Contact Form 7 WordPress plugin from its earliest version up to 4.0.4. No later versions are currently listed as vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests limited likelihood of widespread exploitation. The vulnerability is not cataloged in the CISA Known Exploited Vulnerabilities list, and no publicly disclosed exploit is available. The likely attack vector is a web‑based request to the plugin’s endpoints, inferred from the missing authorization description and the need to reach the WordPress site.
OpenCVE Enrichment