CVE-2026-105990
Received Received - Intake

Unauthenticated Data Export in Contact Form 7 PayPal Payments Plugin

Vulnerability report for CVE-2026-105990, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: WPScan

Description

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Accept PayPal Payments using Contact Form 7 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Accept PayPal Payments using Contact Form 7 WordPress plugin before version 4.0.7. It allows unauthenticated attackers to download personal data and payment metadata from form submissions without any authorization checks.

Detection Guidance

Check if the WordPress plugin 'Accept PayPal Payments using Contact Form 7' is installed and verify its version. If it is below 4.0.7, the vulnerability is likely present. Inspect network traffic for unauthorized data export requests to the plugin's export endpoint.

Impact Analysis

Unauthenticated attackers can access and steal personal data such as names, emails, telephone numbers, postal addresses, messages, and payment details submitted through affected forms. This exposes sensitive information to potential misuse.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access and exposure of personal and payment data. It can lead to non-compliance penalties, legal consequences, and reputational damage for organizations handling such data.

Mitigation Strategies

Update the plugin to version 4.0.7 or later immediately. If an update is unavailable, disable or remove the plugin to prevent unauthorized data access. Review and restrict access to exported data files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105990. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart