What the vulnerability does
01Description
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
Explanation of Vulnerability in Simple Terms
Contact Form 7 – PayPal & Stripe Add-on versions up to 2.5.1 lack proper authorization checks on certain operations. An unauthenticated attacker can modify data or disrupt service availability without needing to log in or interact with a user. Update to a version newer than 2.5.1 to resolve this issue.
What an attacker can do
Modify form data or disrupt service without authentication.
Potential impact on your site
Attackers can alter payment form submissions or cause downtime without a valid account.
Conditions required to exploit
Network access only; no login or user interaction required.
Key dates
External resources
Related vulnerabilities