Unauthorized Payment Processing in CP Contact Form with PayPal Plugin for WordPress
CVE-2025-13384
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 November 2025
What is CVE-2025-13384?
The CP Contact Form with PayPal plugin for WordPress is exposed to a security vulnerability that allows attackers to manipulate payment confirmations without proper authentication. This vulnerability arises from an unauthenticated endpoint that processes payment notifications. Without nonce verification or signature validation, attackers can forge payment requests, marking form submissions as paid without actually completing a transaction. This poses a significant risk to users, allowing unauthorized manipulation of payment statuses.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CP Contact Form with PayPal * <= 1.3.56
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved