Access Control Vulnerability in ZealousWeb PayPal Payments Extension for WordPress
CVE-2026-39707
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-39707?
A missing authorization vulnerability in the ZealousWeb Accept PayPal Payments extension for Contact Form 7 enables attackers to exploit incorrectly configured access control levels. This issue impacts versions from n/a up to and including 4.0.4, potentially allowing unauthorized access and actions within the plugin.
Affected Version(s)
Accept PayPal Payments using Contact Form 7 0 <= 4.0.4