CVE-2026-105989

high

Description

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.

References

https://wpscan.com/vulnerability/df2b15dd-1748-4dcf-8b4f-8c053dc0dd73/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-96123

Details

Source: Mitre, NVD

Published: 2026-10-10

Updated: 2026-10-10

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High