Impact
An unauthenticated user can bypass the plugin’s access control checks when using Contact Form 7 – PayPal & Stripe Add-on versions 2.5.1 or earlier. The flaw permits an attacker to manipulate plugin configuration and payment settings, potentially redirecting funds, injecting malicious code, or exposing sensitive transaction data. This vulnerability directly compromises both the integrity of payment processing and the confidentiality of customer information without requiring credentials.
Affected Systems
The affected product is the Scott Paterson “Contact Form 7 – PayPal & Stripe Add-on” for WordPress. Versions 2.5.1 and older are susceptible. No other version or product is listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.5 categorizes the issue as moderate severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known public exploits as of the last update. The likely attack vector is web-based: an attacker submits crafted requests to the plugin’s administration endpoints without authentication. Because the flaw resides in an administrative function, exploitation requires only access to a publicly exposed WordPress site and the ability to send HTTP requests.
OpenCVE Enrichment