WordPress · Contact Form 7 · CVE-2026-14236
**Name of the Vulnerable Software and Affected Versions**
Contact Form 7 WordPress plugin versions prior to 2.5
**Description**
An unauthenticated attacker can redirect a victim to an arbitrary external site after a Stripe checkout flow by using a crafted link. This occurs because the plugin fails to validate the host of a user-supplied return URL used as the success and cancel redirect targets.
**Recommendations**
Update the plugin to version 2.5 or later.