What the vulnerability does
01Description
Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept PayPal Payments using Contact Form 7: from n/a through <= 4.0.4.
Explanation of Vulnerability in Simple Terms
02Summary
The Accept PayPal Payments using Contact Form 7 plugin for WordPress does not properly check user permissions before allowing certain actions. An attacker without authentication can modify data through the plugin's interface. This affects versions 4.0.4 and earlier. Site owners should update to a version newer than 4.0.4 as soon as a patch is available.
What an attacker can do
03Attacker Capabilities
Modify plugin data or settings without logging in to the site.
Potential impact on your site
04Site Impact
Attackers can alter payment settings, form configurations, or stored data without permission.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
April 8, 2026
CVE published
April 29, 2026
Record updated