WordPress Plugin Vulnerabilities

Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status Forgery

Description

The plugin does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the plugin's status metadata onto arbitrary posts.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Daniel Dhaniswara
Submitter
Daniel Dhaniswara
Verified
Yes

Timeline

Publicly Published
2026-10-08 (about 2 days ago)
Added
2026-10-08 (about 1 day ago)
Last Updated
2026-10-08 (about 1 day ago)

Other