← WordPress Vulnerabilities
WordPress security by component

Contact Form 7 – PayPal & Stripe Add-on

Contact Form 7 – PayPal & Stripe Add-on is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: contact-form-7-paypal-add-on

CVE-2026-14236: Contact Form 7 PayPal and Stripe Add-on permits attacker-controlled checkout redirects

Contact Form 7 – PayPal & Stripe Add-on before 2.5 accepts a caller-controlled cf7pp_return URL in the Stripe checkout flow without validating its destination host. An unauthenticated attacker can prepare a checkout link whose success or cancellation flow redirects a victim to an attacker-controlled site, supporting phishing or credential theft. The upstream changelog says version 2.5 validates the return URL with wp_validate_redirect(), but it does not identify the checkout route or action.

PublishedJul 27, 2026
Known safe version2.5
Safe version
Jul 27, 2026 CVE-2026-14236
Contact Form 7 PayPal and Stripe Add-on permits attacker-controlled checkout redirects
Contact Form 7 – PayPal & Stripe Add-on before 2.5 accepts a caller-controlled cf7pp_return URL in the Stripe checkout flow without validating its destination host. An unauthenticated attacker can prepare a checkout link whose success or cancellation flow redirects a victim to an attacker-controlled site, supporting phishing or credential theft. The upstream changelog says version 2.5 validates the return URL with wp_validate_redirect(), but it does not identify the checkout route or action.
2.5
CVE4.7
NVDPending
May 29, 2026 CVE-2026-9189
Contact Form 7 – PayPal & Stripe Add-on: A security weakness
Contact Form 7 – PayPal & Stripe Add-on is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.4.9.
> 2.4.9
CVE5.3
NVDPending
May 07, 2025 CVE-2025-47518
Contact Form 7 – PayPal & Stripe Add-on: Cross-site scripting
Contact Form 7 – PayPal & Stripe Add-on is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Nov 09, 2024 CVE-2024-10683
Contact Form 7 – PayPal & Stripe Add-on: Cross-site scripting
Contact Form 7 – PayPal & Stripe Add-on is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Oct 17, 2024 CVE-2024-48021
Contact Form 7 – PayPal & Stripe Add-on: Cross-site scripting
Contact Form 7 – PayPal & Stripe Add-on is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Mar 19, 2024 CVE-2024-29130
Contact Form 7 – PayPal & Stripe Add-on: Cross-site scripting
Contact Form 7 – PayPal & Stripe Add-on is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jul 10, 2023 CVE-2023-24405
Contact Form 7 Paypal Add On: Cross-site request forgery
Contact Form 7 Paypal Add On is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8