Unauthorized Payment Processing in CP Contact Form with PayPal Plugin for WordPress
CVE-2025-13384
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 November 2025
What is CVE-2025-13384?
The CP Contact Form with PayPal plugin for WordPress is exposed to a security vulnerability that allows attackers to manipulate payment confirmations without proper authentication. This vulnerability arises from an unauthenticated endpoint that processes payment notifications. Without nonce verification or signature validation, attackers can forge payment requests, marking form submissions as paid without actually completing a transaction. This poses a significant risk to users, allowing unauthorized manipulation of payment statuses.
Affected Version(s)
CP Contact Form with PayPal * <= 1.3.56