Payment Bypass Vulnerability in Contact Form 7 – PayPal & Stripe Add-on for WordPress
CVE-2026-9189

5.3MEDIUM

What is CVE-2026-9189?

The Contact Form 7 – PayPal & Stripe Add-on for WordPress is susceptible to a Payment Bypass vulnerability due to insufficient verification of data authenticity. The plugin fails to validate critical payment details such as the amount (mc_gross), currency (mc_currency), and receiver's email against stored values before completing a transaction. Attackers can exploit this weakness by sending a manipulated Instant Payment Notification (IPN) that references an order. As a result, they can mark high-value pending orders as fully paid by making minimal actual payments. This oversight poses a significant risk, particularly for e-commerce sites relying on accurate payment processing.

Affected Version(s)

Contact Form 7 – PayPal & Stripe Add-on 0 <= 2.4.9

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muni Nitish Kumar Yaddala
.