Description
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated vulnerability in the Pay with Contact Form 7 WordPress plugin allows attackers to read sensitive data exposed by the application. The weakness is classified in CWE-201 and permits disclosure of confidential information without authentication. The CVSS score of 7.5 indicates a high severity, meaning any compromised instance could leak payment or user data.

Affected Systems

The vulnerability affects the cmsMinds Pay with Contact Form 7 WordPress plugin, versions 1.0.4 and earlier. Site owners running these versions are at risk until the issue is patched or the plugin is removed.

Risk and Exploitability

The CVSS rating reflects a considerable potential impact, while the EPSS score of less than 1% indicates a low probability of exploitation, making it unclear how often it is actively exploited. The vulnerability is not listed in the CISA KEV catalog, which suggests no confirmed exploitation yet. Likely attack vectors involve unauthenticated requests to plugin endpoints that return sensitive data; no special credentials or privileged access is required.

Generated by OpenCVE AI on August 20, 2026 at 17:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Pay with Contact Form 7 to a fixed version as soon as it is released by cmsMinds.
  • If an update cannot be applied immediately, restrict access to the plugin’s administration or API pages using role‑based permissions or IP restrictions to block unauthenticated users.
  • Validate and sanitize any user input and output that handles sensitive data to prevent accidental exposure.

Generated by OpenCVE AI on August 20, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Cmsminds
Cmsminds pay With Contact Form 7
Wordpress
Wordpress wordpress
Vendors & Products Cmsminds
Cmsminds pay With Contact Form 7
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
Title WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cmsminds Pay With Contact Form 7
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T15:57:13.136Z

Reserved: 2026-08-12T14:09:17.491Z

Link: CVE-2026-73384

cve-icon Vulnrichment

Updated: 2026-08-20T15:54:21.912Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T13:18:07.650

Modified: 2026-08-20T16:17:54.770

Link: CVE-2026-73384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:10:40Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data