CVE-2026-105989
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 10, 2026
Vendor
unknown
Description
The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.