Unrated severityNVD Advisory· Published Oct 10, 2026
CVE-2026-105989
CVE-2026-105989
Description
The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.0.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.