Sceawere

Vulnerability Detail

CVE-2026-105989UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated PayPal Transaction Metadata Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
8h ago
Vendor
Unknown
Product
Accept PayPal Payments using Contact Form 7
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T06:16:40.547Z",
  "pubdate": "2026-10-10T06:16:40.547Z",
  "executiveSummary": "The Accept PayPal Payments using Contact Form 7 WordPress plugin prior to version 4.0.7 contains a critical security vulnerability involving the lack of authorization and request validation on specific AJAX actions.\nThis vulnerability allows unauthenticated remote attackers to manipulate stored transaction statuses and inject arbitrary metadata into post records within the WordPress database.\nThe flaw stems from a failure to implement proper nonce verification or capability checks, enabling unauthorized parties to execute operations reserved for administrative or authenticated users.\nThe risk implication is significant, as it permits the forgery of financial transaction states and the corruption of post metadata. Such activity could potentially be leveraged for business logic manipulation, unauthorized data modification, or the subversion of internal workflows managed by the plugin.\nAttackers do not require prior authentication or elevated privileges to trigger these AJAX actions, significantly lowering the barrier for exploitation. Affected systems remain vulnerable until the plugin is updated to version 4.0.7 or higher, which addresses the lack of security controls on the affected endpoints.",
  "technicalDetails": "The vulnerability resides within the backend AJAX handling logic of the Accept PayPal Payments using Contact Form 7 WordPress plugin. The root cause is a deficiency in input validation and access control mechanisms, specifically targeting AJAX actions responsible for managing PayPal transaction status data.\nIn the affected versions (pre-4.0.7), the plugin registers AJAX endpoints that are accessible to unauthenticated users. The plugin fails to verify the existence or validity of security nonces (cryptographic tokens used to prevent CSRF and ensure request legitimacy) prior to executing the callback functions associated with these AJAX actions.\nFurthermore, the callback functions lack explicit capability checks, such as current_user_can() calls, which are necessary to ensure that only authorized administrators can perform modifications to database records or post metadata.\nThe attack flow proceeds as follows: 1) An unauthenticated attacker identifies the vulnerable AJAX action endpoint exposed by the plugin. 2) The attacker crafts a malicious HTTP request targeting this endpoint, incorporating custom parameters designed to modify transaction statuses. 3) Because the backend lacks authentication and authorization checks, the server processes the request and executes the update logic. 4) The plugin proceeds to interact with the WordPress database to update or inject status metadata onto arbitrary posts specified by the attacker's payload.\nBy manipulating these parameters, an attacker can effectively deceive the system regarding the state of payments associated with contact forms. This constitutes a severe failure in state management, as the plugin relies on these status records to track financial interactions. Beyond simple forgery, the ability to write metadata onto arbitrary posts exposes the broader WordPress environment to data corruption or logic bypasses, as post meta values are frequently used by other plugins and themes to drive functional behavior.\nThere are no specific environmental conditions or complex exploitation chains required; the request can be sent directly from any remote host, provided the plugin is active. The absence of strict input sanitization ensures that once the unauthorized request is accepted, the database is modified according to the attacker's provided input. Post-exploitation impact includes the loss of integrity regarding financial reporting, potential circumvention of payment-dependent workflows, and the ability to inject metadata that may trigger unexpected behavior in other plugin components that parse post metadata."
}
CVE-2026-105989: Unauthenticated PayPal Transaction Metadata Injection (MEDIUM Severity, CVSS: 5.3) | Sceawere