Impact
The Coinbase Commerce for Contact Form 7 WordPress plugin contains a missing authorization check and nonce verification in its settings save routine. Authenticated users with Subscriber-level capability or higher can exploit this flaw by sending a crafted POST request to the admin-post endpoint, enabling them to overwrite the cccf7_api_key option. This changes the API key used for all Coinbase Commerce transactions, allowing the attacker to redirect payment processing to a different account and potentially siphon funds or cause financial loss.
Affected Systems
The vulnerability affects the coderpress Coinbase Commerce for Contact Form 7 plugin for WordPress, versions up to and including 1.1.2. Users running any of these affected releases are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, but the EPSS score is not available, so exploitation probability is uncertain. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess an authenticated Subscriber or higher role within the WordPress site and to construct a POST request to /wp-admin/admin-post, a local attack that does not rely on external network access.
OpenCVE Enrichment