Unauthorized Payment Processing in CP Contact Form with PayPal Plugin for WordPress
CVE-2025-13384

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 November 2025

What is CVE-2025-13384?

The CP Contact Form with PayPal plugin for WordPress is exposed to a security vulnerability that allows attackers to manipulate payment confirmations without proper authentication. This vulnerability arises from an unauthenticated endpoint that processes payment notifications. Without nonce verification or signature validation, attackers can forge payment requests, marking form submissions as paid without actually completing a transaction. This poses a significant risk to users, allowing unauthorized manipulation of payment statuses.

Affected Version(s)

CP Contact Form with PayPal * <= 1.3.56

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Md. Moniruzzaman Prodhan
.
CVE-2025-13384 : Unauthorized Payment Processing in CP Contact Form with PayPal Plugin for WordPress