CVE-2026-105989
Received Received - Intake

Unauthenticated Post Status Manipulation in Accept PayPal Payments using Contact Form 7

Vulnerability report for CVE-2026-105989, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: WPScan

Description

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Accept PayPal Payments using Contact Form 7 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Accept PayPal Payments using Contact Form 7 WordPress plugin before version 4.0.7. It allows unauthenticated attackers to manipulate transaction status records by exploiting a lack of authorization and request-validation checks in an AJAX action. Attackers can forge stored transaction statuses and overwrite plugin metadata on arbitrary posts.

Detection Guidance

Check the installed version of the 'Accept PayPal Payments using Contact Form 7' plugin. If it is version 4.0.7 or lower, the system is vulnerable. Look for unauthorized changes to post metadata or transaction status records.

Impact Analysis

If you use this plugin, attackers could falsify payment records, leading to incorrect transaction statuses. This may cause financial discrepancies, incorrect order processing, or reputational damage. Unauthorized changes to post metadata could also disrupt site functionality.

Compliance Impact

This vulnerability allows unauthenticated attackers to forge transaction statuses and manipulate plugin metadata, which could lead to unauthorized data modifications. Such unauthorized changes may violate integrity requirements in GDPR and HIPAA, potentially compromising compliance with data accuracy and security controls.

Mitigation Strategies

Update the Accept PayPal Payments using Contact Form 7 WordPress plugin to version 4.0.7 or later to address the lack of authorization checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105989. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart