Unauthenticated Broken Access Control in Contact Form 7 PayPal & Stripe Add-on
CVE-2026-66660

6.5MEDIUM

What is CVE-2026-66660?

The Contact Form 7 PayPal & Stripe Add-on versions equal to or lower than 2.5.1 are susceptible to unauthenticated broken access control. This vulnerability allows unauthorized users to access sensitive functionalities that should only be accessible to authenticated users, creating potential risks for data exposure and exploitation. Websites using this plugin should implement security measures and ensure they are updated to mitigate risks associated with this vulnerability.

Affected Version(s)

Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dodoh4t | Patchstack Bug Bounty Program
.