Vulnerabilities / Accept PayPal Payments using Contact Form 7 / WPSEC-2026-0642
Accept PayPal Payments using Contact Form 7 <= 4.0.6 - Unauthenticated Missing Authorization to Payment Data CSV Export
Medium 5.3
CWE-862Fixed in 4.0.7
- ID
- WPSEC-2026-0642
- Plugin
- Accept PayPal Payments using Contact Form 7 (contact-form-7-paypal-extension)
- Affected
- from 4.0.0 before 4.0.7
- Remediation
- Update to 4.0.7 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-08
- Attack surface
- Accept PayPal Payments using Contact Form 7 on WPSec AttackSurface
- Fix released
- Published
Description
The Accept PayPal Payments using Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the payment submissions CSV export functionality in versions 4.0.0 up to, and including, 4.0.6. This makes it possible for unauthenticated attackers to export stored payment submission records, including transaction IDs, amounts, IP addresses and submitted form data.
References
- https://wpsec.com/vuln/WPSEC-2026-0642/
- https://plugins.svn.wordpress.org/contact-form-7-paypal-extension/tags/4.0.7/
- https://wordpress.org/plugins/contact-form-7-paypal-extension/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS