PT-2026-64847 · WordPress · Contact Form 7
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Contact Form 7 WordPress plugin versions prior to 2.5
Description
An unauthenticated attacker can redirect a victim to an arbitrary external site after a Stripe checkout flow by using a crafted link. This occurs because the plugin fails to validate the host of a user-supplied return URL used as the success and cancel redirect targets.
Recommendations
Update the plugin to version 2.5 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form 7