What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions.
Explanation of Vulnerability in Simple Terms
Contact Form 7 – PayPal & Stripe Add-on versions up to 1.9.3 contain a cross-site request forgery vulnerability. An attacker can craft a malicious link or page that, when visited by a site administrator, performs unwanted actions such as modifying plugin settings or processing unauthorized transactions. The vulnerability requires the admin to click the link or visit the page while logged in.
What an attacker can do
Trick a logged-in admin into modifying plugin settings or processing unauthorized transactions via a malicious link.
Potential impact on your site
An attacker can modify PayPal/Stripe settings or trigger unwanted actions if an admin visits a malicious page.
Conditions required to exploit
Admin must click a malicious link or visit an attacker-controlled page while logged into the WordPress site.
Key dates
External resources
Related vulnerabilities