Payment Bypass Vulnerability in Contact Form 7 β PayPal & Stripe Add-on for WordPress
CVE-2026-9189
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 May 2026
What is CVE-2026-9189?
The Contact Form 7 β PayPal & Stripe Add-on for WordPress is susceptible to a Payment Bypass vulnerability due to insufficient verification of data authenticity. The plugin fails to validate critical payment details such as the amount (mc_gross), currency (mc_currency), and receiver's email against stored values before completing a transaction. Attackers can exploit this weakness by sending a manipulated Instant Payment Notification (IPN) that references an order. As a result, they can mark high-value pending orders as fully paid by making minimal actual payments. This oversight poses a significant risk, particularly for e-commerce sites relying on accurate payment processing.
Affected Version(s)
Contact Form 7 β PayPal & Stripe Add-on 0 <= 2.4.9