CVE-2026-105990

medium

Description

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.

References

https://wpscan.com/vulnerability/211d7613-a7e0-45f9-b262-66651aa4f535/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-96124

Details

Source: Mitre, NVD

Published: 2026-10-10

Updated: 2026-10-10

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium