Impact
An unauthenticated vulnerability in the Pay with Contact Form 7 plugin allows attackers to read sensitive data exposed by the application. The weakness is classified in CWE-201 and permits disclosure of confidential information without authentication. The CVSS score of 7.5 indicates a high severity, meaning any compromised instance could leak payment or user data.
Affected Systems
The vulnerability affects the cmsMinds Pay with Contact Form 7 WordPress plugin, versions 1.0.4 and earlier. Site owners running these versions are at risk until the issue is patched or the plugin is removed.
Risk and Exploitability
The CVSS rating reflects a considerable potential impact, but the EPSS score is not available, making it unclear how often it is actively exploited. The vulnerability is not listed in the CISA KEV catalog, which suggests no confirmed exploitation yet. Likely attack vectors involve unauthenticated requests to plugin endpoints that return sensitive data; no special credentials or privileged access is required.
OpenCVE Enrichment