CVE-2026-14236
Received Received - Intake

Cross-Site Redirect in Contact Form 7 WordPress Plugin

Vulnerability report for CVE-2026-14236, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: WPScan

Description

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
contact_form_7 contact_form_7 to 2.5 (exc)
wpninjas contact_form_7_paypal_and_stripe_add_on to 2.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an open redirect flaw in the Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress, affecting versions before 2.5. An unauthenticated attacker can manipulate the return URL parameter in a Stripe checkout process to redirect victims to an attacker-controlled domain after a legitimate payment. The plugin fails to validate the host of the return URL properly, only checking basic URL format without ensuring it belongs to the same domain.

Detection Guidance

To detect this vulnerability, check the installed version of the Contact Form 7 – PayPal & Stripe Add-on plugin. If the version is below 2.5, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin directory for version details.

Impact Analysis

An attacker could trick you into clicking a malicious link that appears legitimate. After you complete a Stripe payment, you might be redirected to a fake error page controlled by the attacker, potentially leading to phishing attacks, credential theft, or malware downloads. This could compromise your personal or financial information.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling phishing attacks. An attacker could redirect users to malicious sites after a payment, tricking them into disclosing sensitive information. This may violate data protection requirements under GDPR for user consent and security, and HIPAA for safeguarding protected health information during transactions.

Mitigation Strategies

Immediately update the Contact Form 7 – PayPal & Stripe Add-on plugin to version 2.5 or later. If updating is not possible, disable the plugin until an update is applied. Review server logs for suspicious redirect attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14236. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart